Research Lab
Defensive telephony security research
In-depth, cited, defensive analysis of PBX, SIP and VoIP security. We publish only work we can stand behind, and we never claim a vulnerability as our own discovery unless it genuinely is.
In-depth guides
Research & pillar guides
- 9 min read
Caller-ID spoofing and vishing: a defensive guide
How caller-ID spoofing and voice phishing work, why they matter for organisations with phone systems, and the defensive controls that reduce the risk.
Read → - 10 min read
SIP registration security: preventing rogue endpoints
How SIP registration works, why weak registration authentication lets attackers register rogue endpoints and drive toll fraud, and the controls that stop it.
Read → - 9 min read
SRTP and media encryption for VoIP, explained
What SRTP is, why plain RTP media can be intercepted, how media encryption is keyed, and how to verify your VoIP calls are actually protected end to end.
Read → - 13 min read
The complete guide to VoIP security
A defensive, UK-focused guide to securing business VoIP end to end: the attack surface, transport and signalling encryption, media protection with SRTP, endpoints and softphones, hosted versus on-premises responsibilities, fraud, and independent assessment.
Read → - 12 min read
The complete guide to PBX security
A defensive, UK-focused guide to securing a modern PBX: external exposure, authentication, management interfaces, dial-plan design, patching, encryption, logging and independent assessment against NCSC guidance.
Read → - 10 min read
The complete guide to SIP security
A defensive guide to SIP security for UK organisations: how the protocol works, why fraud so often starts here, trunk and registration exposure, authentication, transport security, routing and how an authorised SIP audit works.
Read → - 9 min read
Preventing PBX toll fraud: a defensive guide
A defensive guide to PBX toll fraud for UK organisations: how it happens at a high level, who bears the cost, the controls that stop it, the scale of the problem and why an authorised assessment closes the paths.
Read → - 9 min read
Cloud PBX vs on-premises PBX: the security differences
A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.
Read → - 11 min read
How a PBX security assessment works, step by step
A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.
Read → - 13 min read
The 2026 buyer's guide to PBX and VoIP security testing
A comprehensive buyer's guide to commissioning PBX and VoIP security testing in 2026: what a good assessment includes, scoping and authorisation, technical coverage, reporting standards, retesting, cost drivers, and how to compare suppliers.
Read → - 8 min read
Automated PBX assessment vs traditional penetration testing
A fair comparison of automated PBX assessment and traditional penetration testing across repeatability, telephony focus, cost, human validation and evidence, and where each fits.
Read → - 7 min read
Continuous PBX assurance vs an annual assessment
Why a point-in-time PBX assessment decays as estates change, and the honest case for scheduled automated reassessment, human-validated, rather than always-on real-time monitoring.
Read → - 7 min read
PBX security assessment vs vulnerability scanning
How a telephony-focused PBX security assessment differs from generic vulnerability scanning on context, validation, toll-fraud demonstration and dial-plan review.
Read → - 7 min read
NCSC PBX security guidance: a practical checklist
A practical checklist drawn from the NCSC's PBX best-practice guidance, with the official source linked and notes on where an authorised assessment helps you evaluate the controls.
Read →
The State of PBX Security 2027
We are building the methodology to aggregate anonymised, lawful findings from authorised exposure reviews into an annual report on UK PBX and VoIP exposure. No data is published yet, and nothing customer-identifying will ever appear. When the dataset is genuine and large enough to be meaningful, the report will follow.
We will not publish invented statistics to fill a page. The report ships when the data is real.
PBX Security Briefing
Occasional, high-signal notes on significant PBX and VoIP vulnerabilities, SIP and telecom-fraud developments, and new defensive guidance. Low volume, no spam.
Compare approaches
Buyer education
Compare
Automated assessment vs pen testing
Where each approach is strong, and how they fit together.
Read moreCompare
Assessment vs vulnerability scanning
Why telephony context, validation and evidence matter.
Read moreCompare
Continuous assurance vs annual assessment
The honest case for scheduled periodic reassessment.
Read more
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.