Methodology
How GoldAgent assesses telephony
A defined, repeatable process built around one principle: authorised testing, evidence-led findings, and a fix plan you can act on. No raw scanner output dressed up as a report.
GoldAgent assessments follow a fixed eight-step method: define scope, confirm written authorisation, discover exposure, analyse posture, validate every finding by hand, prioritise by business impact, deliver a dual-audience report, then retest. Active work starts only after authorisation. Findings are evidence-led. Any toll-fraud figure in pounds is an illustrative scenario, not a forecast.
Principles
What holds the method together
Authorised only
Active testing runs against systems you own or are explicitly authorised to test, never anything else.
Human-validated
A person confirms every finding before it reaches you, so the report is signal, not noise.
Risk-prioritised
Findings are ranked by real business impact, not by raw severity scores alone.
Evidence-led
Each finding carries the evidence and the affected service, so your team can reproduce and fix it.
The process
Eight steps, every engagement
The depth varies with the service and the estate; the sequence does not.
- 1
Define scope
We agree the exact systems, addresses and services in scope, and, just as importantly, what is out of scope.
- 2
Confirm authorisation
You confirm ownership or right-to-test in writing before any active work. Hosted systems need the provider's consent where required.
- 3
Discover exposure
We identify the PBX, SIP and management services reachable within the agreed scope, starting from the outside-in view.
- 4
Analyse posture
We assess configuration, authentication, versioning and dialling controls against known telephony risk paths.
- 5
Validate findings
Every finding is confirmed by a person as real and reproducible. False positives are removed before anything reaches your report.
- 6
Prioritise risk
Findings are ranked by severity, exploitability and business impact, so you fix what matters first.
- 7
Deliver the report
A management summary written for decision-makers, plus technical detail, evidence and remediation guidance for your team.
- 8
Retest
Once fixes are applied, we re-check the remediated findings and update their status.
The process runs across twelve control domains, from external exposure to governance. See the GoldAgent PBX Security Framework for what each engagement assesses.
After the first assessment
Assure keeps the picture current
Assess is true on the day it runs. Assure, the flagship annual programme, re-runs the same authorised checks on an agreed cadence. Findings are human-validated. It is scheduled reassessment, not an always-on portal.
Toll-fraud path
Where we look, and what we close
Fraudulent call spend usually needs a reachable service, weak access and a permissive dial plan together. The assessment looks for those weaknesses under written authorisation. It does not place billable fraudulent calls.
Reporting standard
A report two audiences can use
A GoldAgent report is written so a decision-maker can grasp the risk and a technical team can act on it, from the same document.
Every finding includes
- A clear finding title and severity rating
- A plain description and the business impact
- The affected service and supporting evidence
- Specific, actionable remediation guidance
- Retest status once the fix is applied
Any exposure or fraud figure is an illustrative scenario, clearly labelled, not a forecast or an observed loss. Currency is pounds sterling (GBP).
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.