How Bob Mills Furniture Turns Security Findings into Lasting Improvements
Founded in Oklahoma City in 1971, Bob Mills Furniture is a regional furniture retailer with 12 locations across Oklahoma, Texas, and Kansas. The company also operates an online retail presence and supports its stores and business operations through a distributed technology environment.
As Executive Director of IT, John Geddes focuses on ensuring the company’s technology environment remains secure as the business and its technology needs evolve.
While compliance requirements are one reason the team engages in annual penetration testing, John sees the practice as much more than a checkbox.
“A good penetration tester can find issues you never knew you had,” John explained. “It’s not always fun having someone come in and show you where you’ve made mistakes, but for me, penetration testing is something you have to do to stay secure.”
With more than 20 years in IT and experience with penetration testing dating back to 2005, John had worked with multiple testing providers before Halo. Those engagements were adequate, but he often felt the emphasis was on demonstrating what the tester could compromise rather than helping his team understand and reduce risk. John found himself searching Google for other penetration testing options.
Bob Mills Furniture has now completed multiple annual penetration tests with Halo Security. From the first engagement, John noticed a combination of technical depth, professionalism, and practical communication that was an upgrade from previous testing relationships.
On the first test, Halo’s testers uncovered vulnerabilities that had not been previously identified. Just as importantly, they helped him understand the findings, why they mattered, and what needed to change. Rather than simply handing over a report, Halo worked directly with John to walk through the findings and remediation steps.
“The communication was great,” John shared. “The Halo team was responsive, and they didn’t overly geek out or talk over my head. Just smart, efficient, and practical feedback. It was a great experience.”
John continued, “Halo found vulnerabilities during our first test and coached me through them in detail. They also worked with me on the processes and procedures to put in place to make sure we didn’t run into those issues again, and we didn’t.”
When Halo returned for the second annual test, the earlier issues had been fully addressed, and the engagement did not uncover major vulnerabilities. But a shorter list of findings did not mean a less thorough test.
“When they didn’t find anything egregious, they walked me through everything they had tried,” John said. “They explained the exploits they tested and the different ways they tried to get in. That gave me confidence that it was an extensive evaluation, even if the vulnerability findings were minor that year.”
Halo’s penetration testing has helped turn individual findings into lasting security improvements.
John feels Halo provides clear, thorough reporting that helps his team move quickly from discovery to remediation.
“The report was clear and made a lot of sense,” John said. “By the time we scheduled the follow-up conversation, I had already fixed three of the five issues.”
When questions arise, John has direct access to Halo’s team. He said he has never felt like he had to “beg or push or prod” to get the guidance he needed. Halo’s testers are available to explain findings, answer questions, and help him determine the right remediation approach.
After multiple engagements, John sees Halo’s combination of experience, communication, responsiveness, and practical guidance as the differentiator. “They bring more knowledge and real-world, hard-knocks experience to the test,” John said. “They’re very professional in how they handle the engagement and the depth they provide.”
Most importantly, Halo has provided the kind of relationship John was looking for when he began evaluating a new penetration testing provider. “Everybody wants to say they’re a partner while they’re trying to sell you something,” he said. “With Halo, it truly feels like a partnership. They offer to help, they reach out, and they make experts readily available for questions and advice.”
For organizations evaluating their next penetration testing provider, John’s advice is simple: “If you’re considering working with Halo, give them a shot. It’s well worth your time.”