Troy is way overstating the case. You want to know if the login page is NatWest? Click on the Login link and look at the browsers security bar. If it says "The Royal Bank of Scotland Group Plc [GB]" and that then entity with which you do business, great. It seems as if Troy would be just fine with HTTPS rather than HTTP, but DV validated certs aren't what you want anyway with a financial institution. It seems far mor…
The issue is that users tend not to notice the absence of EV security indicators. If they see a padlock (which a phisher could get for a phishing domain), they assume it's secure and enter their credentials. Also, it may not be apparent to users whether "The Royal Bank of Scotland Group Plc [GB]" would be affiliated with NatWest. Companies often have different names they do business under.
If the name is unrecognizable for users, _that_ is the user security concern that you should be posting about.
That handles the widest array of security vulnerabilities on http://personal.natwest.com/, whether MITM, compromised site, misspelled domain, etc.