Bank of America has agreed to acquire information security specialist MDSec Consulting Limited, adding technical firepower to its cyber defences. The deal is expected to close in the fourth quarter of 2026, pending regulatory approval.
Based in Macclesfield, England, MDSec brings about 65 cybersecurity professionals who handle deeply technical information security consultancy.
The deal builds on Bank of America’s footprint in the North of England, where it has more than 1,400 employees in nearby Chester and one of its cyber threat operations centres.
“We have long admired the exceptional ability of the MDSec team and are delighted that Bank of America and its clients will now further benefit from their work,” said Kris Fador, Chief Information Security Officer at Bank of America. “We look forward to welcoming the MDSec team to Bank of America as we continue to enhance our leading cybersecurity capabilities in the UK and globally.”
“We’re immensely proud of what we’ve built at MDSec and, above all, of the team that made it possible,” said Dominic Chell, Co-Founder of MDSec. “From the outset, our ambition has been to build world-class security capabilities and to push the industry forward. Joining one of the world’s leading financial institutions, one that reflects our culture of innovation and technical excellence, gives us an incredible opportunity to take that ambition to the next level.”
Bank of America serves more than 69 million clients through roughly 3,500 retail financial centres, around 15,000 ATMs and some 60 million verified digital users, with operations across the United States, its territories and more than 35 countries and jurisdictions.
The Herald View: Banks used to buy cybersecurity as a service. Now they buy the team outright. Bank of America already runs a threat operations centre a short drive from MDSec’s front door, so this is less a bolt-on than a talent lock-in. With elite security engineers scarce and adversaries AI-armed, owning the expertise beats renting it.
