Skip to content

Methodology

How GoldAgent assesses telephony

A defined, repeatable process built around one principle: authorised testing, evidence-led findings, and a fix plan you can act on. No raw scanner output dressed up as a report.

Principles

What holds the method together

  • Authorised only

    Active testing runs against systems you own or are explicitly authorised to test, never anything else.

  • Human-validated

    A person confirms every finding before it reaches you, so the report is signal, not noise.

  • Risk-prioritised

    Findings are ranked by real business impact, not by raw severity scores alone.

  • Evidence-led

    Each finding carries the evidence and the affected service, so your team can reproduce and fix it.

The process

Eight steps, every engagement

The depth varies with the service and the estate; the sequence does not.

The GoldAgent assessment lifecycleEight stages in order: scope, authorise, discover, analyse, validate, prioritise, report, then retest. Every engagement follows the same sequence.1Scope2Authorise3Discover4Analyse5Validate6Prioritise7Report8Retest
One repeatable sequence, every engagement. The depth varies with the estate; the order does not: Define scopeConfirm authorisationDiscover exposureAnalyse postureValidate findingsPrioritise riskDeliver the reportRetest.
  1. 1

    Define scope

    We agree the exact systems, addresses and services in scope, and, just as importantly, what is out of scope.

  2. 2

    Confirm authorisation

    You confirm ownership or right-to-test in writing before any active work. Hosted systems need the provider's consent where required.

  3. 3

    Discover exposure

    We identify the PBX, SIP and management services reachable within the agreed scope, starting from the outside-in view an attacker has.

  4. 4

    Analyse posture

    We assess configuration, authentication, versioning and dialling controls against known telephony attack paths.

  5. 5

    Validate findings

    Every finding is confirmed by a person as real and reproducible. False positives are removed before anything reaches your report.

  6. 6

    Prioritise risk

    Findings are ranked by severity, exploitability and business impact, so you fix what matters first.

  7. 7

    Deliver the report

    A management summary written for decision-makers, plus technical detail, evidence and remediation guidance for your team.

  8. 8

    Retest

    Once fixes are applied, we re-check the remediated findings and update their status.

The process runs across twelve control domains, from external exposure to governance. See the GoldAgent PBX Security Framework for what each engagement assesses.

Reporting standard

A report two audiences can use

A GoldAgent report is written so a decision-maker can grasp the risk and a technical team can act on it, from the same document.

Every finding includes

  • A clear finding title and severity rating
  • A plain description and the business impact
  • The affected service and supporting evidence
  • Specific, actionable remediation guidance
  • Retest status once the fix is applied

Any exposure or fraud figure is an illustrative scenario, clearly labelled, not a forecast or an observed loss.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.