Skip to content
Specialist telephony security

Know exactly how exposed your PBX and VoIP systems are

GoldAgent performs authorised PBX, SIP and VoIP security assessments to uncover configuration weaknesses, needless exposure and toll-fraud risk before they become expensive incidents.

Testing is performed only against systems you own or are explicitly authorised to test.

Authorised exposure map in scope
SIP trunk serviceExposed
Admin interfaceRestricted
Extension rangeReview
Firmware versionOutdated
Outbound routingPermissive
Risk score62 / 100

Illustrative representation of assessment output. Not live data.

  • Authorised, scoped testing
  • Human-validated findings
  • Telephony-specialist, not generalist
  • UK-based, sold nationally

GoldAgent runs authorised PBX, SIP and VoIP security assessments for UK organisations. Assess is a point-in-time review with a full report. Assure, the flagship annual programme, repeats the authorised checks on a schedule and a person validates each cycle. A free exposure check uses public data only: we do not log in, probe, or send traffic to the phone system. MSP partners can white-label the work where commercially agreed.

The problem

Phone systems sit outside most security programmes

PBX and VoIP platforms are installed once, connected to the internet for administration or SIP trunking, and then left. That is exactly why attackers scan for them, and why the telephony layer is so often the weakest point.

  • Exposed management services

    Administration interfaces reachable from the public internet, often protected by nothing more than a password.

  • Weak authentication

    Default, reused or guessable credentials on administrative and SIP accounts, with no lockout on repeated attempts.

  • Permissive dialling

    Outbound and premium-rate routes left wide open: the exposure that turns a compromise into fraudulent call spend.

  • Forgotten accounts

    Test extensions and departed-staff logins that were never disabled and no longer belong to anyone.

  • Ageing firmware

    PBX and VoIP software running versions with known, published vulnerabilities that never get patched.

  • No monitoring

    No logging or alerting on the systems that carry every inbound and outbound call.

How toll fraud typically reaches a phone billA defensive map of a common toll-fraud path: an exposed telephony service, a weak or forgotten account, a hijacked extension, a permissive dial plan, then fraudulent call spend the business is usually liable for. Closing any of the first four steps breaks the path. The diagram does not describe how to attack a system.1Exposed serviceSIP or admin reachablefrom the public internet2Weak accountGuessable, default orforgotten login3Hijacked extensionAttacker can placecalls as that user4Open dial planInternational andpremium routes left on5Fraudulent spendThe business isusually liableBreak the pathRestrict what is reachable · strengthen accounts · apply least privilege to outbound calling · alert on unusual spendClosing any of the first four steps prevents the fifth. A GoldAgent assessment finds which steps are open on your estate.
Toll fraud is a path, not a single bug. An exposed service plus a weak account plus a permissive dial plan is what turns a compromise into a bill. Restricting exposure, authentication or outbound routing at any step stops the spend. This is a defensive map, not an attack guide.

The GoldAgent approach

Specialist telephony expertise, validated by people

We combine deep PBX and SIP knowledge with a repeatable assessment engine and human validation, so you get findings that are real, ranked by business risk, and ready to act on.

  • Telephony-specific checks a generalist scanner does not run
  • Every finding validated by a person before it reaches your report
  • Risk prioritised by exploitability and business impact
  • Clear, evidenced remediation your team can implement
  • A defined retest path to confirm the fixes worked
  • Scheduled reassessment that re-checks for new exposure between assessments

What you receive

Every assessment produces a management-ready deliverable, not a raw scanner dump.

  • Executive summary
  • Technical findings
  • Severity ratings & evidence
  • Prioritised remediation
  • Exposure inventory
  • Retest status

The GoldAgent lifecycle

From what's exposed to what's assured

Every engagement follows the same outcome-led path. Authorisation is confirmed before any active work begins, and the final stage, Assure, runs the checks on a schedule and tracks changes run to run, with findings human-validated.

The GoldAgent assurance lifecycleSix stages in order: Discover, Validate, Prioritise, Remediate, Verify, then Assure. Authorisation is confirmed before any active work. Assure is scheduled reassessment, not always-on monitoring.1DiscoverSee what is exposed2ValidateConfirm what is real3PrioritiseKnow what matters first4RemediateFix with clear guidance5VerifyProve it is closed6AssureKeep it currentAuthorised assessment, then scheduled reassessment · GoldAgent Assure is the flagship
From what is exposed to what is assured. Every engagement follows the same path: Discover → Validate → Prioritise → Remediate → Verify → Assure. Assure re-runs the authorised checks on a schedule; it is not an always-on monitoring platform.
  1. 1

    Discover

    See what is exposed

    Identify the PBX, SIP and VoIP infrastructure reachable within your authorised scope, starting from the outside-in view an attacker has.

  2. 2

    Validate

    Confirm what is real

    A person confirms which findings are genuinely exploitable and, where authorised, demonstrates impact, so you act on evidence, not scanner noise.

  3. 3

    Prioritise

    Know what matters first

    Rank findings by severity, exploitability and business impact, with a risk score and an illustrative view of fraud exposure.

  4. 4

    Remediate

    Fix with clear guidance

    Each finding carries specific, actionable remediation your team can implement: patch, restrict, tighten or segment.

  5. 5

    Verify

    Prove it is closed

    Retest the remediated findings to confirm the weakness is genuinely gone and the fix introduced no new gap.

  6. 6

    Assure

    Keep it current

    Run the authorised checks on a schedule and diff each run against the last: new, resolved and unchanged findings tracked over time. Automated runs, human-validated findings.

How we compare

Specialist depth a scanner or general test misses

A fair, category-level comparison. Many organisations pair a broad scanner or penetration test with specialist telephony assessment. This shows what GoldAgent adds.

How GoldAgent compares with generic scanning, traditional penetration testing and general autonomous security platforms across telephony-security dimensions.
DimensionGeneric vulnerability scannerTraditional penetration testGeneral autonomous platformGoldAgent
PBX / SIP specialismDepth of telephony-specific coverage: SIP, trunks, dial-plan, AMI, toll fraud.
Repeatable, consistent methodSame checks run the same way each time, so results are comparable over time.
Human validation of findingsA person confirms findings are real and removes false positives before reporting.
Toll-fraud demonstrationEvidence of whether fraudulent outbound calling is genuinely possible, under agreed limits.
Dial-plan & routing reviewReviews the calling permissions where most telephony fraud risk actually lives.
Prioritised remediation guidance
Retest / verificationRe-checks remediated findings to confirm they are genuinely closed.
Recurring assuranceGoldAgent delivers scheduled, automated reassessment with historical change tracking; findings are human-validated. No live portal.
Machine-readable output (SARIF)Findings that flow into SIEM and security pipelines.
Low procurement complexity for SMEs
Suited to MSP / multi-site deliveryCan be packaged and delivered across many customer estates.

This compares categories of approach, not named companies. Each has legitimate strengths; many organisations combine a broad scanner or pen test with specialist telephony assessment.

The deliverable

See exactly what you get

The report is the product. Explore an interactive, sanitised sample: executive and technical views, severity, evidence, remediation and retest status.

  • Executive summary + risk score /100
  • Per-finding severity, evidence & remediation
  • Retest status: open / remediated / verified
  • Exports: HTML, JSON, CSV, SARIF
Shape of a GoldAgent assessment reportAn illustrative layout of a GoldAgent report: a header with a scope hash, an overall risk score out of 100, a severity breakdown, an illustrative fraud figure clearly labelled as a scenario, and three sample findings with severity and retest status. Fictional data only.SAMPLE REPORT · ILLUSTRATIVEPBX Security Assessmentscope hash 3f1c…a9e2RISK SCORE62/100SEVERITY3H2M1LILLUSTRATIVE SCENARIO£4,000–£9,000Not a forecast or observed lossHighManagement console reachable externallyRetestHighPermissive international dial planOpenMedProvisioning service unrestrictedOpenFictional sample. Evidence, remediation and retest live in the full report.
What the report looks like. A header with the authorised scope, a risk score out of 100, findings by severity, and an illustrative fraud figure in pounds sterling, labelled as a scenario rather than a forecast. The interactive sample below uses the same fictional data.

Exposure changes; an assessment does not

  • A firewall rule is changed and reopens exposure
  • Remote administration is switched on for a supplier
  • A trunk is migrated or a new endpoint deployed
  • A new vulnerability is published for your platform vendor
The GoldAgent assessment-and-assurance timelineA one-off authorised assessment at the start, then the same authorised checks re-run on an agreed schedule and validated by a person each cycle, so evidence stays current. It depicts discrete scheduled cycles, not always-on monitoring.estate drifts · new issuesAssessAuthorisedpoint-in-time1Assure2Assure3Assure4AssureSame authorised checks · re-run on your cadence · human-validated
Assess once; Assure keeps it current. A point-in-time assessment is true on the day it runs. Assure re-runs the same authorised checks on an agreed schedule and a person validates each cycle, so drift and newly disclosed issues are caught. It is scheduled reassessment, not an always-on monitoring platform.

GoldAgent Assure

The flagship: keep the estate current after the first assessment

A point-in-time assessment is true on the day it is run. GoldAgent Assure, the flagship, runs the authorised checks on a schedule and compares each run against the last, tracking new, resolved and unchanged findings over time. Runs are automated; findings are human-validated. No customer portal; reports come to you directly. From £1,290 a year, indicative GBP.

Who we help

Where telephony risk is highest

The exposure is common; the business impact is not. These sectors feel it most.

  • Industry

    Call & Contact Centres

    High call volumes and always-on telephony make exposure and fraud costly.

    Read more
  • Industry

    Healthcare

    Legacy estates and sensitive lines raise the stakes on telephony security.

    Read more
  • Industry

    Finance & Professional Services

    Card-by-phone and regulatory pressure make telephony security a control, not an option.

    Read more
  • Channel

    MSPs & Telecom Providers

    White-label PBX and VoIP security to add telephony assurance to your stack.

    Read more

FAQ

Common questions

What does GoldAgent actually do?

GoldAgent runs authorised security assessments of PBX, VoIP and SIP telephony. It finds exposed services, weak authentication, permissive dialling and toll-fraud risk, then delivers evidenced, prioritised findings your team can act on.

Is this legal, and what do you test?

We test only systems you own or are explicitly authorised to test. Every active assessment starts with confirmed scope and written authorisation. Where a hosted provider's consent is required, we confirm it before any active work begins.

Will testing disrupt our live phones?

Assessments are planned around your environment, with lockout-aware techniques and an agreed emergency-stop contact. Higher-impact tests are only run with your explicit agreement, and any recurring reassessment is scheduled and non-intrusive.

Do you work with MSPs and telecom providers?

Yes. MSP white-label is the growth motion: we offer white-label PBX and VoIP security for MSPs and resellers who want to add telephony assurance to their stack without building the specialism in-house.

Is there a way to start without an authorised assessment?

Yes. The free UK PBX Exposure Check uses public data only. We do not log in, probe, or send traffic to the phone system. Assess (from £800) and Assure, the flagship annual programme (from £1,290), follow if you want authorised testing.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.