# Bank of America Is Buying MDSec — and That Should Make Every Red Teamer Pay Attention
When a bank with a $3.2 trillion balance sheet acquires an offensive security consultancy out of Macclesfield, England, the press release will tell you it's about "technical excellence" and "expanding UK presence." That's not wrong. It's just not the whole story.
Bank of America confirmed Thursday it plans to acquire MDSec Consulting Limited, a UK-based information security firm employing roughly 65 professionals. The deal is expected to close in Q4 2026, pending regulatory sign-off. Financial terms were not disclosed — which, for a firm this size, probably means the number was either embarrassingly small or strategically sensitive.
## This Is Not Just Another Headcount Acquisition
MDSec isn't a generic cybersecurity shop. Anyone who follows offensive security research knows the name. The firm has been a fixture in red team and adversary simulation work for years, and co-founder Dominic Chell has a reputation in the community that goes well beyond standard-issue security consulting. MDSec's research has touched everything from Active Directory attack paths to commercial C2 infrastructure — the kind of deep technical work that most financial institutions pay outside vendors to do.
That's exactly the point. Bank of America isn't buying 65 warm bodies for their Chester cyber threat operations center. They're buying a specific capability set — one that has historically lived outside the perimeter of most corporate security programs.
This distinction matters enormously. Offensive security talent is scarce, doesn't scale cleanly, and doesn't stay put when market rates spike. Acquiring a whole firm with an established culture and internal research pipeline is a qualitatively different move than posting a dozen red team engineer positions on LinkedIn and hoping.
## The Insourcing Imperative in Financial Services
The deal fits a pattern that's been building for several years across Tier 1 financial institutions. JPMorgan, Goldman Sachs, and Citigroup have all dramatically expanded internal security headcount, and the direction has been increasingly toward offensive capability — not just detection and response.
The reasoning is straightforward, even if it took banks a while to get there: if your threat models include nation-state actors and sophisticated criminal groups, you can't understand your own attack surface by reading vendor reports. You need people who think offensively, who actually know how adversaries operate, and who can stress-test defenses before the adversaries do.
External red team engagements have always had a fundamental limitation — they're episodic. A firm comes in for two weeks, produces a report, and leaves. The institutional knowledge walks out the door. Bringing that capability in-house means continuity, direct access to production environments, and the ability to run persistent adversary simulation programs rather than point-in-time assessments.
Bank of America's existing cyber threat operations center in Chester — with over 1,400 employees nearby — makes the geographic logic obvious. MDSec's Macclesfield office is a short commute from Chester. This is consolidation of regional talent, not a transatlantic remote-work bet.
## What 65 People Actually Gets You
Sixty-five professionals sounds modest for a bank of BofA's scale. But in offensive security, 65 people with the right background is a legitimately significant force multiplier — provided they're integrated properly rather than absorbed into a compliance-heavy bureaucracy that neutralizes what made them valuable.
That's the real risk in deals like this. Corporate environments, especially regulated financial institutions, are often structurally hostile to the kind of autonomous, research-driven work that made MDSec worth acquiring. The talent disperses, the culture flattens, and in 18 months you have 65 people writing internal security reports instead of finding the novel attack paths that justified the acquisition.
Chell's statement — that joining BofA gives them "an incredible opportunity to take that ambition to the next level" — is exactly what you'd expect him to say. Whether it's true depends on how much operational latitude BofA actually grants the team, which won't be visible from the outside for some time.
## The Regulatory Layer Nobody's Talking About
There's a dimension to this deal that deserves more attention: the UK regulatory environment.
Post-Brexit, UK financial services firms operate under the Financial Conduct Authority's increasingly aggressive cybersecurity expectations, including the incoming DORA-equivalent requirements that UK regulators are developing. Having internal offensive security capability isn't just a technical advantage — it's becoming a regulatory expectation for systemically important financial institutions.
The FCA and PRA have been moving toward requiring banks to demonstrate that they've genuinely tested their defenses against realistic adversary scenarios, not just checked compliance boxes. A dedicated internal red team with MDSec's background is a much more credible answer to a regulator asking "how do you know your controls work?" than pointing at an annual penetration test report from a third party.
This might be the quietest but most durable driver of the deal.
---
## HackWire Analysis
The MDSec acquisition is a signal, not just a transaction. We're watching the offensive security talent market undergo a structural shift — and financial services is leading it.
For years, the model was clear: banks hire MSSPs and consultancies for security work, keep headcount lean, and buy capability as a service. That model is breaking down at the high end. The most sophisticated threat actors — the ones that actually keep bank CISOs awake — aren't deterred by SLAs and quarterly reports. They probe continuously, adapt, and exploit the gaps between assessments.
The response from institutions that can afford it is internalization of the capability that matters most: the ability to think like an attacker. MDSec represents exactly that capability, and BofA is paying whatever the number was to own it outright.
The ripple effect for defenders outside the megabank tier is worth watching. As Tier 1 institutions absorb boutique offensive firms, mid-market companies will find the external red team vendor landscape increasingly thin at the top. The best firms get acquired. What's left serves the compliance-checkbox market. Organizations that haven't built meaningful internal security research capability — and can't afford to buy it — will find themselves increasingly dependent on threat intelligence products that describe what happened to other people, rather than finding their own vulnerabilities first.
The answer isn't to despair about talent consolidation. It's to recognize that the economics of offensive security are changing, and to invest in training and internal capability development now, before the acqui-hire wave makes external expertise even harder to access.
— HackWire Editorial
---
## Related Coverage