Bank of America has acquired MDSec, a UK-based information security consultancy, for an undisclosed amount. The deal brings the British firm, known for its specialised expertise in application, mobile, and hardware security, under the full ownership of the US banking group. MDSec will operate as a wholly owned subsidiary, with its team of experienced consultants remaining in place to continue client work.
MDSec’s core business centres on targeted red team attacks and simulated adversarial exercises. The consultancy holds accreditations that allow it to work with the UK government’s technical authority CESG under the CHECK service, and it partners with the Bank of England and CREST to deliver simulated attacks under the CBEST framework. Its client base spans financial institutions and public sector bodies, though specific customer names were not disclosed. The firm also runs training courses that appear regularly at conferences such as BlackHat, 44Con, and OWASP AppSec.
For Bank of America, the acquisition addresses a growing need to strengthen internal cyber defences against sophisticated threats. By owning MDSec outright, the bank gains direct access to a team that understands both offensive security techniques and the regulatory expectations of the UK financial sector. This is particularly relevant given MDSec’s existing relationships with the Bank of England and its familiarity with CBEST, a framework designed to test the resilience of systemically important firms.
The strategic rationale extends beyond immediate security operations. MDSec’s educational focus and conference presence could support Bank of America’s broader efforts to train its own security staff and raise awareness of emerging attack vectors. The consultancy’s UK base also aligns with the bank’s existing European footprint, though no changes to MDSec’s day-to-day operations or client engagements have been announced.
The combined entity will now offer a more integrated approach to offensive security testing within a major financial institution. MDSec’s consultants are expected to continue serving external clients while also supporting internal Bank of America teams, though the balance between these roles has not been specified. The deal is closed, and no further financial terms have been made public.

