Skip to content

Research Lab

Defensive telephony security research

In-depth, cited, defensive analysis of PBX, SIP and VoIP security. We publish only work we can stand behind, and we never claim a vulnerability as our own discovery unless it genuinely is.

In-depth guides

Research & pillar guides

  • 9 min read

    Caller-ID spoofing and vishing: a defensive guide

    How caller-ID spoofing and voice phishing work, why they matter for organisations with phone systems, and the defensive controls that reduce the risk.

    Read →
  • 10 min read

    SIP registration security: preventing rogue endpoints

    How SIP registration works, why weak registration authentication lets attackers register rogue endpoints and drive toll fraud, and the controls that stop it.

    Read →
  • 9 min read

    SRTP and media encryption for VoIP, explained

    What SRTP is, why plain RTP media can be intercepted, how media encryption is keyed, and how to verify your VoIP calls are actually protected end to end.

    Read →
  • 13 min read

    The complete guide to VoIP security

    A defensive, UK-focused guide to securing business VoIP end to end: the attack surface, transport and signalling encryption, media protection with SRTP, endpoints and softphones, hosted versus on-premises responsibilities, fraud, and independent assessment.

    Read →
  • 12 min read

    The complete guide to PBX security

    A defensive, UK-focused guide to securing a modern PBX: external exposure, authentication, management interfaces, dial-plan design, patching, encryption, logging and independent assessment against NCSC guidance.

    Read →
  • 10 min read

    The complete guide to SIP security

    A defensive guide to SIP security for UK organisations: how the protocol works, why fraud so often starts here, trunk and registration exposure, authentication, transport security, routing and how an authorised SIP audit works.

    Read →
  • 9 min read

    Preventing PBX toll fraud: a defensive guide

    A defensive guide to PBX toll fraud for UK organisations: how it happens at a high level, who bears the cost, the controls that stop it, the scale of the problem and why an authorised assessment closes the paths.

    Read →
  • 9 min read

    Cloud PBX vs on-premises PBX: the security differences

    A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.

    Read →
  • 11 min read

    How a PBX security assessment works, step by step

    A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.

    Read →
  • 13 min read

    The 2026 buyer's guide to PBX and VoIP security testing

    A comprehensive buyer's guide to commissioning PBX and VoIP security testing in 2026: what a good assessment includes, scoping and authorisation, technical coverage, reporting standards, retesting, cost drivers, and how to compare suppliers.

    Read →
  • 8 min read

    Automated PBX assessment vs traditional penetration testing

    A fair comparison of automated PBX assessment and traditional penetration testing across repeatability, telephony focus, cost, human validation and evidence, and where each fits.

    Read →
  • 7 min read

    Continuous PBX assurance vs an annual assessment

    Why a point-in-time PBX assessment decays as estates change, and the honest case for scheduled automated reassessment, human-validated, rather than always-on real-time monitoring.

    Read →
  • 7 min read

    PBX security assessment vs vulnerability scanning

    How a telephony-focused PBX security assessment differs from generic vulnerability scanning on context, validation, toll-fraud demonstration and dial-plan review.

    Read →
  • 7 min read

    NCSC PBX security guidance: a practical checklist

    A practical checklist drawn from the NCSC's PBX best-practice guidance, with the official source linked and notes on where an authorised assessment helps you evaluate the controls.

    Read →
In preparation

The State of PBX Security 2027

We are building the methodology to aggregate anonymised, lawful findings from authorised exposure reviews into an annual report on UK PBX and VoIP exposure. No data is published yet, and nothing customer-identifying will ever appear. When the dataset is genuine and large enough to be meaningful, the report will follow.

We will not publish invented statistics to fill a page. The report ships when the data is real.

PBX Security Briefing

Occasional, high-signal notes on significant PBX and VoIP vulnerabilities, SIP and telecom-fraud developments, and new defensive guidance. Low volume, no spam.

Compare approaches

Buyer education

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.