Why the heck is Bank of America buying a tiny offensive security firm?

Bank of America doesn’t make acquisitions like this every day, folks. The financial giant announced it plans to acquire MDSec Consulting, a United Kingdom-based information security consultancy with roughly 65 employees. Financial terms were not disclosed, and the deal is expected to close during the fourth quarter of 2026, subject to regulatory approvals.

At first glance, the announcement might not seem particularly noteworthy. Banks buy companies, and cybersecurity has become one of the industry’s biggest priorities. But the size of the target makes this acquisition stand out. It made me pause and say huh?

Look, MDSec is not a household name, nor is it a massive cybersecurity vendor with thousands of employees or a broad portfolio of commercial products. Instead, it specializes in highly technical information security consulting, including offensive security work such as penetration testing, red teaming, exploit research, and security assessments.

That raises an interesting question: Why would one of the world’s largest financial institutions acquire a company this small instead of simply hiring more security professionals? Well, one possible answer is that elite offensive security talent is difficult to build from scratch.

Finding experienced researchers who can identify vulnerabilities before attackers do is challenging enough. Keeping an established team together may be even harder. By acquiring MDSec, Bank of America isn’t just gaining individual employees. It is also acquiring an experienced team with an existing culture, proven workflows, and years of institutional knowledge.

The wording of Bank of America’s announcement seems to support that idea. Rather than focusing on products or intellectual property, the company repeatedly highlighted the MDSec team and its technical expertise.

That doesn’t necessarily mean MDSec’s consulting business will continue operating as it does today. In fact, that’s quite unlikely. I would predict that the firm’s specialists will become part of Bank of America’s internal cybersecurity organization, helping defend the bank’s systems, test its security posture, and improve its ability to detect and respond to increasingly sophisticated threats.

The move also reflects a scary reality facing large enterprises. Cybersecurity is no longer just about buying software. Organizations are increasingly investing in people who can think like attackers, uncover weaknesses before criminals find them, and strengthen defenses through continuous testing.

Will this acquisition become a model for other financial institutions? Who the hell knows. However, it does suggest that experienced offensive security teams have become valuable enough that, in some cases, buying the entire company may be easier than trying to recruit its employees one by one.

What do you think? Is Bank of America making a smart investment in hard-to-find cybersecurity talent, or does acquiring a 65-person consultancy seem like an unusual way to strengthen its security capabilities?

Support independent tech journalism

NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.

Support NERDS.xyz
Written by

Brian Fagioli

Technology journalist and founder of NERDS.xyz

Brian Fagioli is a technology journalist and founder of NERDS.xyz. A former BetaNews writer, he has spent over a decade covering Linux, hardware, software, cybersecurity, and AI with a no nonsense approach for real nerds.

Leave a Comment