Skip to content

Methodology

How GoldAgent assesses telephony

A defined, repeatable process built around one principle: authorised testing, evidence-led findings, and a fix plan you can act on. No raw scanner output dressed up as a report.

GoldAgent assessments follow a fixed eight-step method: define scope, confirm written authorisation, discover exposure, analyse posture, validate every finding by hand, prioritise by business impact, deliver a dual-audience report, then retest. Active work starts only after authorisation. Findings are evidence-led. Any toll-fraud figure in pounds is an illustrative scenario, not a forecast.

Principles

What holds the method together

  • Authorised only

    Active testing runs against systems you own or are explicitly authorised to test, never anything else.

  • Human-validated

    A person confirms every finding before it reaches you, so the report is signal, not noise.

  • Risk-prioritised

    Findings are ranked by real business impact, not by raw severity scores alone.

  • Evidence-led

    Each finding carries the evidence and the affected service, so your team can reproduce and fix it.

The process

Eight steps, every engagement

The depth varies with the service and the estate; the sequence does not.

The GoldAgent assessment lifecycleEight stages in order: scope, authorise, discover, analyse, validate, prioritise, report, then retest. Every engagement follows the same sequence.1Scope2Authorise3Discover4Analyse5Validate6Prioritise7Report8Retest
One repeatable sequence, every engagement. The depth varies with the estate; the order does not: Define scope → Confirm authorisation → Discover exposure → Analyse posture → Validate findings → Prioritise risk → Deliver the report → Retest.
  1. 1

    Define scope

    We agree the exact systems, addresses and services in scope, and, just as importantly, what is out of scope.

  2. 2

    Confirm authorisation

    You confirm ownership or right-to-test in writing before any active work. Hosted systems need the provider's consent where required.

  3. 3

    Discover exposure

    We identify the PBX, SIP and management services reachable within the agreed scope, starting from the outside-in view.

  4. 4

    Analyse posture

    We assess configuration, authentication, versioning and dialling controls against known telephony risk paths.

  5. 5

    Validate findings

    Every finding is confirmed by a person as real and reproducible. False positives are removed before anything reaches your report.

  6. 6

    Prioritise risk

    Findings are ranked by severity, exploitability and business impact, so you fix what matters first.

  7. 7

    Deliver the report

    A management summary written for decision-makers, plus technical detail, evidence and remediation guidance for your team.

  8. 8

    Retest

    Once fixes are applied, we re-check the remediated findings and update their status.

The process runs across twelve control domains, from external exposure to governance. See the GoldAgent PBX Security Framework for what each engagement assesses.

The GoldAgent PBX Security Framework, mappedTwelve control domains grouped into four themes: Reach (external exposure, administrative security, segmentation), Access (identity and authentication, endpoints, dial-plan and fraud), Protect (signalling, media, configuration and patch) and Assure (monitoring, resilience, governance).Reachwhat's exposedGA-PBX-01External exposureGA-PBX-06Admin securityGA-PBX-07SegmentationAccessgetting inGA-PBX-02Identity & authGA-PBX-08EndpointsGA-PBX-05Dial-plan & fraudProtectthe call & platformGA-PBX-03SignallingGA-PBX-04MediaGA-PBX-11Config & patchAssurestaying secureGA-PBX-09MonitoringGA-PBX-10ResilienceGA-PBX-12Governance
Twelve domains, one system. Grouped into four themes so nothing is missed: Reach (external exposure, admin security, segmentation); Access (identity & auth, endpoints, dial-plan & fraud); Protect (signalling, media, config & patch); Assure (monitoring, resilience, governance).

After the first assessment

Assure keeps the picture current

Assess is true on the day it runs. Assure, the flagship annual programme, re-runs the same authorised checks on an agreed cadence. Findings are human-validated. It is scheduled reassessment, not an always-on portal.

The GoldAgent assessment-and-assurance timelineA one-off authorised assessment at the start, then the same authorised checks re-run on an agreed schedule and validated by a person each cycle, so evidence stays current. It depicts discrete scheduled cycles, not always-on monitoring.estate drifts · new issuesAssessAuthorisedpoint-in-time1Assure2Assure3Assure4AssureSame authorised checks · re-run on your cadence · human-validated
Assess once; Assure keeps it current. A point-in-time assessment is true on the day it runs. Assure re-runs the same authorised checks on an agreed schedule and a person validates each cycle, so drift and newly disclosed issues are caught. It is scheduled reassessment, not an always-on monitoring platform.

Toll-fraud path

Where we look, and what we close

Fraudulent call spend usually needs a reachable service, weak access and a permissive dial plan together. The assessment looks for those weaknesses under written authorisation. It does not place billable fraudulent calls.

How toll fraud typically reaches a phone billA defensive map of a common toll-fraud path: an exposed telephony service, a weak or forgotten account, a hijacked extension, a permissive dial plan, then fraudulent call spend the business is usually liable for. Closing any of the first four steps breaks the path. The diagram does not describe how to attack a system.1Exposed serviceSIP or admin reachablefrom the public internet2Weak accountGuessable, default orforgotten login3Hijacked extensionAttacker can placecalls as that user4Open dial planInternational andpremium routes left on5Fraudulent spendThe business isusually liableBreak the pathRestrict what is reachable · strengthen accounts · apply least privilege to outbound calling · alert on unusual spendClosing any of the first four steps prevents the fifth. A GoldAgent assessment finds which steps are open on your estate.
Toll fraud is a path, not a single bug. An exposed service plus a weak account plus a permissive dial plan is what turns a compromise into a bill. Restricting exposure, authentication or outbound routing at any step stops the spend. This is a defensive map, not an attack guide.

Reporting standard

A report two audiences can use

A GoldAgent report is written so a decision-maker can grasp the risk and a technical team can act on it, from the same document.

Every finding includes

  • A clear finding title and severity rating
  • A plain description and the business impact
  • The affected service and supporting evidence
  • Specific, actionable remediation guidance
  • Retest status once the fix is applied

Any exposure or fraud figure is an illustrative scenario, clearly labelled, not a forecast or an observed loss. Currency is pounds sterling (GBP).

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.