Skip to content

Assessment framework

The GoldAgent PBX Security Framework

Twelve control domains that define what a telephony security assessment should cover, from external exposure to governance. It is the structure behind every GoldAgent engagement, and a checklist you can hold any provider to.

Telephony security fails in predictable places. The GoldAgent PBX Security Framework names those places as twelve control domains, so an assessment covers the whole system rather than whatever a scanner happens to flag. Each domain sets out what it protects, what weakness looks like, and the evidence a GoldAgent assessment produces for it.

What this is, and is not. This is GoldAgent's own assessment framework, informed by established guidance from NCSC, NIST, the IETF and OWASP. It is not an industry standard, certification or accreditation, and it implies no endorsement by any of those bodies.

Version 1.0 · First published August 2026 · Last reviewed August 2026

The shape of the risk

The telephony attack surface

Exposure runs from the internet, through the services a phone system leaves reachable, to the platform and out to endpoints, trunks and media. The framework assesses each element.

The PBX and VoIP attack surfaceA left-to-right flow from the internet to a PBX or VoIP platform through its exposed services, then out to endpoints, SIP trunks and media. Each element maps to a GoldAgent control domain.InternetUntrustedExposed servicesSIP · managementprovisioningPBX / VoIP platformConfiguration · patch postureEndpoints & softphonesProvisioning · firmwareSIP trunks / SBCCarrier · dial planMedia (RTP / SRTP)Call audioEvery element maps to a control domain in the GoldAgent PBX Security Framework.
The telephony attack surface, mapped. An assessment follows this shape, internet to platform to endpoints, trunks and media, and evaluates each element against the control domains:
  • Internet · External exposure
  • Exposed services · External exposure · Administrative security
  • PBX / VoIP platform · Configuration & patch posture
  • Endpoints & softphones · Endpoint security
  • SIP trunks / SBC · Dial-plan & fraud controls
  • Media (RTP / SRTP) · Media protection

The twelve domains

What a complete telephony assessment covers

Every GoldAgent finding maps back to one of these domains, so you see your posture domain by domain, not as an undifferentiated list.

The GoldAgent PBX Security Framework, mappedTwelve control domains grouped into four themes: Reach (external exposure, administrative security, segmentation), Access (identity and authentication, endpoints, dial-plan and fraud), Protect (signalling, media, configuration and patch) and Assure (monitoring, resilience, governance).Reachwhat's exposedGA-PBX-01External exposureGA-PBX-06Admin securityGA-PBX-07SegmentationAccessgetting inGA-PBX-02Identity & authGA-PBX-08EndpointsGA-PBX-05Dial-plan & fraudProtectthe call & platformGA-PBX-03SignallingGA-PBX-04MediaGA-PBX-11Config & patchAssurestaying secureGA-PBX-09MonitoringGA-PBX-10ResilienceGA-PBX-12Governance
Twelve domains, one system. Grouped into four themes so nothing is missed: Reach (external exposure, admin security, segmentation); Access (identity & auth, endpoints, dial-plan & fraud); Protect (signalling, media, config & patch); Assure (monitoring, resilience, governance).
  • GA-PBX-01

    External exposure

    What of the phone system is reachable from the internet.

    Risk if weak: Management consoles, SIP and provisioning services left open to the public internet are scanned continuously and are the starting point of most remote compromises.

    What we assess: We map the outside-in view of your estate: the SIP, signalling and management services reachable from outside your network, and confirm what should not be there.

    Limitations: Reflects services reachable from the agreed external vantage points at the time of testing. Services behind additional access controls, or brought online afterwards, are out of view unless separately scoped.

  • GA-PBX-02

    Identity & authentication

    Who can register endpoints, place calls and administer the platform.

    Risk if weak: Default or weak credentials, shared accounts and missing multi-factor authentication let an attacker register a rogue endpoint or take over administration.

    What we assess: We check credential strength, default-account handling, SIP registration authentication and whether administrative access requires strong, individual authentication.

    Limitations: Assesses authentication controls observable and testable under authorisation, within agreed limits. It does not perform unrestricted credential cracking and cannot judge staff password hygiene not represented in the system.

  • GA-PBX-03

    Signalling protection

    The SIP messages that set up, control and tear down calls.

    Risk if weak: SIP sent in the clear exposes call metadata and credentials and can be tampered with in transit. Obsolete TLS configurations are a common finding in older deployments.

    What we assess: We verify that signalling is carried over TLS where required, using current protocol versions and validated certificates rather than deprecated settings.

    Limitations: Verifies signalling protection for the paths in scope. Carrier-side or third-party segments outside your control are noted where visible but not independently tested.

  • GA-PBX-04

    Media protection

    The audio of the call itself.

    Risk if weak: Plain RTP can be captured and replayed by anyone on the media path. A frequent gap is signalling protected with TLS while the media still falls back to unencrypted RTP.

    What we assess: We confirm whether media is encrypted with SRTP for the calls that matter, and that key exchange is tied to secure signalling rather than left open.

    Limitations: Confirms media protection for representative call paths. A point-in-time assessment cannot guarantee that every possible call route was exercised.

  • GA-PBX-05

    Dial-plan & fraud controls

    What the system is permitted to dial, and at whose cost.

    Risk if weak: A permissive dial plan combined with a compromised extension is the classic toll-fraud path: expensive calls the business is usually liable for, placed without anyone noticing.

    What we assess: We review outbound-calling permissions, premium and international routing, and the least-privilege controls that limit fraudulent call spend.

    Limitations: Reviews configured calling permissions and routing and demonstrates fraud paths safely. It does not place live fraudulent calls, and any exposure figure is an illustrative scenario, not a forecast or observed loss.

  • GA-PBX-06

    Administrative security

    The management and provisioning surfaces that control everything else.

    Risk if weak: Exposed or weakly protected web consoles and provisioning services are the highest-value target: control of administration is control of the whole estate.

    What we assess: We assess the management interfaces and provisioning services for exposure, authentication, and common web-application weaknesses.

    Limitations: Covers the management surfaces disclosed in scope. Bespoke integrations or admin tooling not surfaced during scoping are not assessed.

  • GA-PBX-07

    Network segmentation

    How voice is isolated from the rest of the network.

    Risk if weak: Flat networks let a foothold anywhere reach the voice estate, and weak segmentation exposes signalling and media that should never be broadly reachable.

    What we assess: We look at how voice is separated from data, how remote access to voice services is controlled, and where segmentation is assumed but not enforced.

    Limitations: Evaluates segmentation evidence available from the tested vantage points. It is not a full internal network audit unless separately scoped.

  • GA-PBX-08

    Endpoint security

    Handsets, softphones and the provisioning that configures them.

    Risk if weak: Default passwords, ageing firmware and provisioning over unencrypted channels turn endpoints into an easy way in, and a provisioning file can leak the credentials it carries.

    What we assess: We review endpoint hardening, firmware currency, and whether provisioning is protected as the credential store it effectively is.

    Limitations: Assesses a representative sample of endpoint and provisioning configuration. It does not physically inspect every handset in the estate.

  • GA-PBX-09

    Monitoring & detection

    Your ability to notice abuse before it becomes a bill or a breach.

    Risk if weak: Without call-detail review and alerting, toll fraud and misuse run until the invoice arrives. Most telephony compromise is visible in the records, if anyone is looking.

    What we assess: We assess whether call-detail records, logging and alerting are in place and capable of surfacing fraudulent or anomalous calling.

    Limitations: Assesses whether logging and alerting capability exists and is capable. It does not operate as, or replace, a staffed monitoring function.

  • GA-PBX-10

    Resilience & availability

    Keeping the phones working when something goes wrong.

    Risk if weak: An exposed, unpatched PBX is a single point of failure for every inbound and outbound call, and voice services can be knocked offline by volumetric attacks.

    What we assess: We consider single points of failure, exposure to disruption, and the resilience of the paths your calls depend on.

    Limitations: Considers exposure to disruption and single points of failure from a security standpoint. It is not a full availability or disaster-recovery audit.

  • GA-PBX-11

    Configuration & patch posture

    The versions and settings the platform actually runs.

    Risk if weak: Configuration drifts and firmware ages while nobody watches the telephony layer, leaving known-vulnerable versions and permissive defaults in place for years.

    What we assess: We assess platform versioning against known telephony weaknesses and review the configuration against a hardened baseline rather than the vendor default.

    Limitations: Assesses versioning and configuration observable during testing. Vendor-undisclosed internals and closed-source components are out of scope.

  • GA-PBX-12

    Governance & assurance

    That the controls above stay true as the estate changes.

    Risk if weak: A point-in-time assessment is true on the day it is run. Without recurring review, evidence decays as extensions accumulate, suppliers change and configuration drifts.

    What we assess: We work under written authorisation and an agreed scope, deliver evidence rather than assumptions, and through Assure we re-run the authorised checks on a schedule so your evidence stays current.

    Limitations: Covers the assurance process GoldAgent operates for the telephony estate. It does not assess wider organisational governance beyond that estate.

Framework, meet method

The domains are what; the methodology is how

The framework tells you the control areas that matter. Our methodology is the repeatable process we run across them: scope, authorisation, discovery, analysis, validation, prioritisation, reporting and retest, with every finding confirmed by a person before it reaches your report.

Assess against it

Put the framework to work

An authorised assessment measures your estate against all twelve domains and shows you where you stand, with evidence and a prioritised fix plan. Continuous Assurance keeps that picture current by re-running the authorised checks on a schedule.

Grounded in real guidance

Standards and guidance referenced

The framework is informed by primary, authoritative sources, not marketing. We cite the current guidance, and note where older references have been superseded.

Versioned

Framework version 1.0

The framework is versioned so you can cite a specific edition. Material changes are recorded here.

  • v1.0 · August 2026

    First published version. Twelve control domains, each with a stable control ID (GA-PBX-01 to GA-PBX-12), defensive risk framing, the evidence a GoldAgent assessment produces, primary-source references, and a stated limitation.

Questions

About the framework

Is the GoldAgent PBX Security Framework an industry standard or certification?
No. It is GoldAgent's own assessment framework: the control domains we examine during an authorised telephony assessment. It is informed by established guidance from NCSC, NIST, the IETF and OWASP, but it is not a standard, certification or accreditation, and it implies no endorsement by those bodies.
How does the framework relate to a GoldAgent assessment?
The twelve domains are what we assess; the methodology is how we assess them. Each engagement moves through scope, authorisation, discovery, analysis, validation, prioritisation, reporting and retest, and every finding is mapped back to one of these control domains so you can see your posture domain by domain.
Does the framework apply to hosted and cloud VoIP as well as on-premises PBX?
Yes. The domains are platform-agnostic. With a hosted or UCaaS service the provider owns some controls and you own others, so the framework is used to make that shared responsibility explicit rather than assumed.

Related reading: the complete guide to PBX security and the complete guide to VoIP security.

Assess your estate against all twelve domains

An authorised GoldAgent assessment shows you where you stand on each control domain, with evidence and a clear fix plan.

Testing is only performed against systems you own or are explicitly authorised to test.