Summary
- The proposed acquisition is expected to complete in the fourth quarter of 2026, subject to regulatory approval.
- Macclesfield-based MDSec employs approximately 65 people and specialises in technical security consultancy and research.
- Integration will test whether the bank can retain the team’s specialist capability, culture, and capacity to challenge internal assumptions.
Bank of America plans to acquire UK security consultancy MDSec, bringing a specialist technical team into a financial institution that already operates a substantial cyber function nearby.
Bank of America said the transaction is expected to complete during the fourth quarter of 2026, subject to regulatory approval. The financial terms have not been disclosed.
MDSec is based in Macclesfield and employs approximately 65 cybersecurity professionals. Its work includes adversary simulation, application security, penetration testing, incident response, research, and technical training.
The bank already employs more than 1,400 people in nearby Chester, where it operates one of its cyber threat operations centres. The acquisition therefore adds to an existing regional operation rather than creating an isolated capability in a new location.
For Bank of America, the transaction offers direct access to a concentrated technical team and the knowledge built through consultancy work across different systems and organisations. For MDSec, it provides the resources and internal estate of a global financial institution.
The value of the acquisition will depend heavily on staff retention. Specialist consultancies are not conventional asset purchases: much of their capability sits with practitioners, research culture, internal methods, and the credibility developed through repeated technical work.
Those assets can weaken quickly if experienced staff leave or if integration changes the conditions under which the team operates. Compensation, autonomy, career structure, research time, and the ability to publish technical work may all affect whether the bank retains the expertise it is acquiring.
Independence presents a second challenge. Adversary simulation and penetration testing are intended to question assumptions held by system owners, technology teams, and management. A team brought inside the same institution it is testing must retain enough authority and organisational distance to report weaknesses that are inconvenient or expensive to address.
Internal ownership can also create advantages. Testers can develop a deeper understanding of architecture, identity systems, payment platforms, cloud deployments, and recurring control failures than is normally possible through a short external engagement.
Findings can move more directly into remediation and resilience work, while repeated testing can measure whether earlier weaknesses were corrected or merely displaced. A permanent team may also be available during incidents without the procurement and onboarding delays associated with an emergency consultancy engagement.
The trade-off is breadth. External consultancies work across clients and encounter different technologies, attack paths, and organisational failures. An internal team can gain exceptional depth in one environment but may lose exposure to unfamiliar systems unless it maintains active research and industry engagement.
The acquisition also reflects the strategic value placed on offensive and technical-security capability by large financial institutions. Testing is increasingly applied to cloud platforms, identity systems, software development, and operational resilience rather than being treated solely as a periodic compliance exercise.
Neither company has disclosed how MDSec will be structured after completion, whether it will continue serving external clients, or how its research and training activities will change. Those decisions will determine whether the deal operates mainly as an internal capability acquisition or retains a broader services role.
Regulatory approval remains outstanding, and the transaction may still be subject to conditions. Completion will mark the beginning rather than the end of the operational work.
Bank of America is acquiring a relatively small organisation whose value lies in specialised people and methods. Preserving that value inside a much larger institution will require the bank to retain the team’s technical focus and its ability to challenge the environment it has joined.


