Free resource
The Business PBX Security Checklist
A working checklist of 23 defensive controls your IT team can use to review a phone system, from external exposure to monitoring. Print it or save it as a PDF.
1External exposure
- Confirm which telephony services are reachable from the internet.
- Ensure management and administration interfaces are not publicly exposed.
- Restrict remote administration to known addresses or a VPN.
- Remove or firewall any exposed service that does not need to be reachable.
2Accounts and authentication
- Change every default credential on the PBX, endpoints and management tools.
- Enforce strong, unique passwords on administrative and SIP accounts.
- Enable multi-factor authentication wherever the platform supports it.
- Disable unused extensions, test accounts and departed-staff logins.
- Confirm registration and login attempts are rate-limited and locked out.
3Dialling and fraud controls
- Restrict international and premium-rate dialling to accounts that need it.
- Disable call routes the business never uses.
- Set out-of-hours and volume limits where the platform allows.
- Enable alerting on unusual calling patterns.
4Patching and maintenance
- Track firmware and application versions against vendor advisories.
- Apply security updates on a defined cycle.
- Review the configuration after any migration or supplier change.
5Network and access
- Separate management access from normal user traffic.
- Control and review third-party and supplier access.
- Restrict access to call recordings and configuration exports.
6Monitoring and resilience
- Enable logging on the systems that carry your calls.
- Ensure logs are reviewed, not just collected.
- Alert on administrative changes and unusual registration activity.
- Confirm backups of the phone-system configuration exist and restore cleanly.
Want it confirmed independently?
A checklist closes the obvious gaps. An authorised assessment confirms what is actually exposed, validates which weaknesses are real, and prioritises them.
© 2026 GoldAgent. This checklist is defensive guidance for reviewing systems you own or are authorised to manage. It is not a guarantee of security.
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.