Start with a passive exposure review
A low-commitment first look at what your phone system exposes to the public internet. It uses public data only (the outside-in view an attacker starts from) so it needs no authorisation and touches nothing on your systems.
Public data only. No active probing. No passwords or credentials required.