
BofA keeps shopping — this time for cyber muscle
Bank of America said it plans to acquire MDSec Consulting Limited, a London-based information security specialist. The deal is expected to close in the fourth quarter of 2026, assuming regulators don’t throw a wrench in the works.
Why you should care
This isn’t some flashy, mega-deal that rewrites the bank’s whole identity. But it does tell you where the priorities are: security, resilience, and fewer sleepless nights for the folks guarding customer data. In banking, cyber defense is less “nice to have” and more “please don’t let the internet eat our lunch.”
The bigger picture
Banks have been acting like cybersecurity is the new branch network — expensive, necessary, and everywhere. Buying a specialist like MDSec gives BofA more in-house know-how as digital threats get nastier and regulators keep the pressure on.
If you’re watching BAC, the takeaway is pretty simple: this is a modest bolt-on deal, not a blockbuster. But it fits the broader story of big banks fortifying the digital moat around their businesses.
Big picture: sometimes the smartest acquisition is the one that helps you avoid the headline nobody wants.
