Bank of America to buy UK's MDSec Consulting to bolster cyber defenses
According to PYMNTS, Bank of America is moving to acquire MDSec Consulting, a UK-based information security firm with roughly 65 specialists — a deal that, on the surface, looks like a corporate IT…
Jocelyn Davenport·updated August 02, 2026

According to PYMNTS, Bank of America is moving to acquire MDSec Consulting, a UK-based information security firm with roughly 65 specialists — a deal that, on the surface, looks like a corporate IT story but, underneath, is about the changing shape of financial risk.
The acquisition, expected to close in the fourth quarter pending regulatory approval, pulls MDSec into a bank that already runs a cyber threat operations center in Chester and employs more than 1,400 people across England. CISO Kris Fador framed it as a talent play: "We have long admired the exceptional ability of the MDSec team."
What MDSec actually brings
MDSec isn't a consumer brand. It's the kind of firm banks call when something has already gone wrong, or when they want to make sure it doesn't. Co-founder Dominic Chell struck a familiar chord in the announcement: "From the outset, our ambition has been to build world-class security capabilities and to push the industry forward."
For us — the people whose login screens and transfer confirmations sit on top of all this defensive infrastructure — the real question isn't whether MDSec is impressive. It's whether the deal tightens the seams we never see, or simply adds another layer of brand polish to a perimeter that's already creaking under its own weight.
The AI pressure underneath the press release
The timing is the tell. Two weeks before this acquisition surfaced, CEO Brian Moynihan told Bloomberg Television that AI tools — specifically Anthropic's Mythos model — are redrawing the workload for security teams. "It is a big change in the amount of work that will have to go on and the pace [at] which these tools will affect vulnerabilities in your systems," he said. The bank has also recently named a new head of platforms AI transformation.
Read those moves together and the pattern is hard to miss: the threat surface is widening faster than any in-house team can patch, and BoA is buying depth of talent because rewriting the architecture itself would take too long.
What changes for us — and what doesn't
None of us will open our banking app tomorrow and notice anything different. That's the point, and it's also the problem. When a bank spends on cybersecurity, the product of that spend is the absence of a bad day — no frozen account, no drained balance, no awkward call to the fraud line. The cognitive load we carry as customers stays invisible precisely because someone, somewhere, is absorbing it on our behalf.
The longer question is whether legacy giants can keep purchasing their way to resilience, or whether the neobanks we've been watching — built with security woven into the architecture rather than bolted on afterward — will keep edging ahead on the trust axis. For now, BoA is betting that bringing in 65 specialists is faster than rebuilding. We'll be watching whether that bet shows up in the metrics that actually count: fewer frozen accounts, faster fraud resolution, and the sense that the bank protects our attention as carefully as it protects our money.