Assessment framework
The GoldAgent PBX Security Framework
Twelve control domains that define what a telephony security assessment should cover, from external exposure to governance. It is the structure behind every GoldAgent engagement, and a checklist you can hold any provider to.
Telephony security fails in predictable places. The GoldAgent PBX Security Framework names those places as twelve control domains, so an assessment covers the whole system rather than whatever a scanner happens to flag. Each domain sets out what it protects, what weakness looks like, and the evidence a GoldAgent assessment produces for it.
Version 1.0 · First published August 2026 · Last reviewed August 2026
The shape of the risk
The telephony attack surface
Exposure runs from the internet, through the services a phone system leaves reachable, to the platform and out to endpoints, trunks and media. The framework assesses each element.
- Internet · External exposure
- Exposed services · External exposure · Administrative security
- PBX / VoIP platform · Configuration & patch posture
- Endpoints & softphones · Endpoint security
- SIP trunks / SBC · Dial-plan & fraud controls
- Media (RTP / SRTP) · Media protection
The twelve domains
What a complete telephony assessment covers
Every GoldAgent finding maps back to one of these domains, so you see your posture domain by domain, not as an undifferentiated list.
- GA-PBX-01
External exposure
What of the phone system is reachable from the internet.
Risk if weak: Management consoles, SIP and provisioning services left open to the public internet are scanned continuously and are the starting point of most remote compromises.
What we assess: We map the outside-in view of your estate: the SIP, signalling and management services reachable from outside your network, and confirm what should not be there.
Limitations: Reflects services reachable from the agreed external vantage points at the time of testing. Services behind additional access controls, or brought online afterwards, are out of view unless separately scoped.
- GA-PBX-02
Identity & authentication
Who can register endpoints, place calls and administer the platform.
Risk if weak: Default or weak credentials, shared accounts and missing multi-factor authentication let an attacker register a rogue endpoint or take over administration.
What we assess: We check credential strength, default-account handling, SIP registration authentication and whether administrative access requires strong, individual authentication.
Limitations: Assesses authentication controls observable and testable under authorisation, within agreed limits. It does not perform unrestricted credential cracking and cannot judge staff password hygiene not represented in the system.
- GA-PBX-03
Signalling protection
The SIP messages that set up, control and tear down calls.
Risk if weak: SIP sent in the clear exposes call metadata and credentials and can be tampered with in transit. Obsolete TLS configurations are a common finding in older deployments.
What we assess: We verify that signalling is carried over TLS where required, using current protocol versions and validated certificates rather than deprecated settings.
Limitations: Verifies signalling protection for the paths in scope. Carrier-side or third-party segments outside your control are noted where visible but not independently tested.
- GA-PBX-04
Media protection
The audio of the call itself.
Risk if weak: Plain RTP can be captured and replayed by anyone on the media path. A frequent gap is signalling protected with TLS while the media still falls back to unencrypted RTP.
What we assess: We confirm whether media is encrypted with SRTP for the calls that matter, and that key exchange is tied to secure signalling rather than left open.
Limitations: Confirms media protection for representative call paths. A point-in-time assessment cannot guarantee that every possible call route was exercised.
- GA-PBX-05
Dial-plan & fraud controls
What the system is permitted to dial, and at whose cost.
Risk if weak: A permissive dial plan combined with a compromised extension is the classic toll-fraud path: expensive calls the business is usually liable for, placed without anyone noticing.
What we assess: We review outbound-calling permissions, premium and international routing, and the least-privilege controls that limit fraudulent call spend.
Limitations: Reviews configured calling permissions and routing and demonstrates fraud paths safely. It does not place live fraudulent calls, and any exposure figure is an illustrative scenario, not a forecast or observed loss.
- GA-PBX-06
Administrative security
The management and provisioning surfaces that control everything else.
Risk if weak: Exposed or weakly protected web consoles and provisioning services are the highest-value target: control of administration is control of the whole estate.
What we assess: We assess the management interfaces and provisioning services for exposure, authentication, and common web-application weaknesses.
Limitations: Covers the management surfaces disclosed in scope. Bespoke integrations or admin tooling not surfaced during scoping are not assessed.
- GA-PBX-07
Network segmentation
How voice is isolated from the rest of the network.
Risk if weak: Flat networks let a foothold anywhere reach the voice estate, and weak segmentation exposes signalling and media that should never be broadly reachable.
What we assess: We look at how voice is separated from data, how remote access to voice services is controlled, and where segmentation is assumed but not enforced.
Limitations: Evaluates segmentation evidence available from the tested vantage points. It is not a full internal network audit unless separately scoped.
- GA-PBX-08
Endpoint security
Handsets, softphones and the provisioning that configures them.
Risk if weak: Default passwords, ageing firmware and provisioning over unencrypted channels turn endpoints into an easy way in, and a provisioning file can leak the credentials it carries.
What we assess: We review endpoint hardening, firmware currency, and whether provisioning is protected as the credential store it effectively is.
Limitations: Assesses a representative sample of endpoint and provisioning configuration. It does not physically inspect every handset in the estate.
- GA-PBX-09
Monitoring & detection
Your ability to notice abuse before it becomes a bill or a breach.
Risk if weak: Without call-detail review and alerting, toll fraud and misuse run until the invoice arrives. Most telephony compromise is visible in the records, if anyone is looking.
What we assess: We assess whether call-detail records, logging and alerting are in place and capable of surfacing fraudulent or anomalous calling.
Limitations: Assesses whether logging and alerting capability exists and is capable. It does not operate as, or replace, a staffed monitoring function.
- GA-PBX-10
Resilience & availability
Keeping the phones working when something goes wrong.
Risk if weak: An exposed, unpatched PBX is a single point of failure for every inbound and outbound call, and voice services can be knocked offline by volumetric attacks.
What we assess: We consider single points of failure, exposure to disruption, and the resilience of the paths your calls depend on.
Limitations: Considers exposure to disruption and single points of failure from a security standpoint. It is not a full availability or disaster-recovery audit.
- GA-PBX-11
Configuration & patch posture
The versions and settings the platform actually runs.
Risk if weak: Configuration drifts and firmware ages while nobody watches the telephony layer, leaving known-vulnerable versions and permissive defaults in place for years.
What we assess: We assess platform versioning against known telephony weaknesses and review the configuration against a hardened baseline rather than the vendor default.
Limitations: Assesses versioning and configuration observable during testing. Vendor-undisclosed internals and closed-source components are out of scope.
- GA-PBX-12
Governance & assurance
That the controls above stay true as the estate changes.
Risk if weak: A point-in-time assessment is true on the day it is run. Without recurring review, evidence decays as extensions accumulate, suppliers change and configuration drifts.
What we assess: We work under written authorisation and an agreed scope, deliver evidence rather than assumptions, and through Assure we re-run the authorised checks on a schedule so your evidence stays current.
Limitations: Covers the assurance process GoldAgent operates for the telephony estate. It does not assess wider organisational governance beyond that estate.
Framework, meet method
The domains are what; the methodology is how
The framework tells you the control areas that matter. Our methodology is the repeatable process we run across them: scope, authorisation, discovery, analysis, validation, prioritisation, reporting and retest, with every finding confirmed by a person before it reaches your report.
Assess against it
Put the framework to work
An authorised assessment measures your estate against all twelve domains and shows you where you stand, with evidence and a prioritised fix plan. Continuous Assurance keeps that picture current by re-running the authorised checks on a schedule.
Grounded in real guidance
Standards and guidance referenced
The framework is informed by primary, authoritative sources, not marketing. We cite the current guidance, and note where older references have been superseded.
Versioned
Framework version 1.0
The framework is versioned so you can cite a specific edition. Material changes are recorded here.
v1.0 · August 2026
First published version. Twelve control domains, each with a stable control ID (GA-PBX-01 to GA-PBX-12), defensive risk framing, the evidence a GoldAgent assessment produces, primary-source references, and a stated limitation.
Questions
About the framework
- Is the GoldAgent PBX Security Framework an industry standard or certification?
- No. It is GoldAgent's own assessment framework: the control domains we examine during an authorised telephony assessment. It is informed by established guidance from NCSC, NIST, the IETF and OWASP, but it is not a standard, certification or accreditation, and it implies no endorsement by those bodies.
- How does the framework relate to a GoldAgent assessment?
- The twelve domains are what we assess; the methodology is how we assess them. Each engagement moves through scope, authorisation, discovery, analysis, validation, prioritisation, reporting and retest, and every finding is mapped back to one of these control domains so you can see your posture domain by domain.
- Does the framework apply to hosted and cloud VoIP as well as on-premises PBX?
- Yes. The domains are platform-agnostic. With a hosted or UCaaS service the provider owns some controls and you own others, so the framework is used to make that shared responsibility explicit rather than assumed.
Related reading: the complete guide to PBX security and the complete guide to VoIP security.
Assess your estate against all twelve domains
An authorised GoldAgent assessment shows you where you stand on each control domain, with evidence and a clear fix plan.
Testing is only performed against systems you own or are explicitly authorised to test.