Methodology
How GoldAgent assesses telephony
A defined, repeatable process built around one principle: authorised testing, evidence-led findings, and a fix plan you can act on. No raw scanner output dressed up as a report.
Principles
What holds the method together
Authorised only
Active testing runs against systems you own or are explicitly authorised to test, never anything else.
Human-validated
A person confirms every finding before it reaches you, so the report is signal, not noise.
Risk-prioritised
Findings are ranked by real business impact, not by raw severity scores alone.
Evidence-led
Each finding carries the evidence and the affected service, so your team can reproduce and fix it.
The process
Eight steps, every engagement
The depth varies with the service and the estate; the sequence does not.
- 1
Define scope
We agree the exact systems, addresses and services in scope, and, just as importantly, what is out of scope.
- 2
Confirm authorisation
You confirm ownership or right-to-test in writing before any active work. Hosted systems need the provider's consent where required.
- 3
Discover exposure
We identify the PBX, SIP and management services reachable within the agreed scope, starting from the outside-in view an attacker has.
- 4
Analyse posture
We assess configuration, authentication, versioning and dialling controls against known telephony attack paths.
- 5
Validate findings
Every finding is confirmed by a person as real and reproducible. False positives are removed before anything reaches your report.
- 6
Prioritise risk
Findings are ranked by severity, exploitability and business impact, so you fix what matters first.
- 7
Deliver the report
A management summary written for decision-makers, plus technical detail, evidence and remediation guidance for your team.
- 8
Retest
Once fixes are applied, we re-check the remediated findings and update their status.
The process runs across twelve control domains, from external exposure to governance. See the GoldAgent PBX Security Framework for what each engagement assesses.
Reporting standard
A report two audiences can use
A GoldAgent report is written so a decision-maker can grasp the risk and a technical team can act on it, from the same document.
Every finding includes
- A clear finding title and severity rating
- A plain description and the business impact
- The affected service and supporting evidence
- Specific, actionable remediation guidance
- Retest status once the fix is applied
Any exposure or fraud figure is an illustrative scenario, clearly labelled, not a forecast or an observed loss.
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.