If you run a phone system, you have probably been offered both an automated security assessment and a traditional penetration test, and it is not always obvious how they differ or which you need. They are not the same exercise, and neither is a straight replacement for the other. This article sets out where each approach is strong, where it is limited, and how a business can decide which to commission for its PBX.
What each method actually is
A traditional penetration test is a time-boxed, human-led engagement. A tester is given a scope and a window, and works to find and exploit weaknesses much as an attacker would, then writes up what they found. The output reflects the skill of the individual and the depth of the scope you agreed.
An automated assessment uses tooling to enumerate a system against a known set of checks. It runs the same tests the same way every time, which makes it fast and repeatable. On its own it produces findings rather than a demonstrated, business-relevant story of impact.
GoldAgent works in the telephony layer specifically, on PBX, SIP and VoIP estates, and combines automated enumeration with human validation of what the tooling reports. The comparison below is meant to help you choose sensibly, not to dismiss either approach.
Repeatability and consistency
Automation is consistent by design. Run it in March and again in September and the method is identical, so you can compare results over time and see whether an estate is improving or drifting. That consistency also removes the variability that comes from different individuals interpreting the same scope differently.
A traditional test is only as repeatable as the tester's notes and the rigour of the methodology behind it. Good firms document thoroughly, but two tests months apart can still diverge in coverage. If your priority is a stable baseline you can re-run, automation has the edge.
Telephony specialism
A general penetration test usually covers networks, web applications and infrastructure, with telephony as one item among many. That breadth is useful, but a PBX has its own failure modes: dial-plan misconfiguration, unauthenticated SIP registration, weak trunk credentials, exposed management interfaces and international call routing that can be abused for revenue-share fraud.
The FreePBX vulnerability CVE-2025-57819, rated CVSS 10.0 and listed in the CISA Known Exploited Vulnerabilities catalogue, is a reminder that telephony platforms carry critical, exploited weaknesses of their own. Assessing them well needs someone who understands how the platform is meant to behave.
Cost and frequency
Human-led tests are priced by tester time, so depth and cost move together. That is appropriate for a one-off, deep engagement, but it makes frequent repetition expensive. Many organisations end up testing once a year and living with the gaps in between.
Automated assessment lowers the marginal cost of each run, which makes more frequent checking affordable. The trade is that speed alone does not tell you which findings truly matter to your business. The figures below are illustrative, not a forecast, and simply show the shape of the decision.
- A deep annual penetration test: higher cost per engagement, strong depth, infrequent by necessity.
- Automated assessment: lower cost per run, broad and repeatable coverage, needs interpretation.
- Automated assessment with human validation: repeatable coverage plus confirmed, prioritised findings.
Human validation and evidence
The weakness of unvalidated automation is false positives and false confidence. A tool may flag an issue that is not exploitable in your configuration, or miss a chained weakness that only a person would spot. Validation is where a human confirms whether a reported issue is real and what it would let an attacker do.
Evidence is what turns a finding into something a board, an auditor or an insurer will act on. A demonstrated toll-fraud path, with the request and response that proves it, is far more persuasive than a line item in a scanner report. Both a traditional test and a validated automated assessment can produce this; raw automation usually cannot.
What each is best for
Choose a traditional penetration test when you need maximum depth against a defined target, creative attacker thinking across many layers, or a bespoke engagement tied to a specific project such as a major migration.
Choose an automated assessment when you need a repeatable telephony baseline, affordable re-checks as the estate changes, and consistent evidence you can track over time. In practice most organisations benefit from both, used for what each does well.
How GoldAgent approaches it
GoldAgent runs automated enumeration focused on PBX, SIP and VoIP, then applies human validation so that reported issues are confirmed and, where safe and authorised, demonstrated. The aim is the repeatability of automation with the credibility that only validation and evidence provide.
All testing is carried out only with written authorisation and an agreed scope. This is a defensive service intended to help you understand and reduce exposure, not a substitute for a broad, whole-estate penetration test where that is what you need.
Sources
Related service
PBX Security Assessment
An authorised, end-to-end assessment of the PBX systems your business runs on.
Related reading
- Cloud PBX vs on-premises PBX: the security differences
A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.
- How a PBX security assessment works, step by step
A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.
- The 2026 buyer's guide to PBX and VoIP security testing
A comprehensive buyer's guide to commissioning PBX and VoIP security testing in 2026: what a good assessment includes, scoping and authorisation, technical coverage, reporting standards, retesting, cost drivers, and how to compare suppliers.
- PBX security assessment vs vulnerability scanning
How a telephony-focused PBX security assessment differs from generic vulnerability scanning on context, validation, toll-fraud demonstration and dial-plan review.
This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.