A single security assessment tells you where an estate stood on the day it was tested. Phone systems do not stand still, and the picture starts to age the moment the report is delivered. This article explains why point-in-time results decay, and makes an honest case for scheduled periodic reassessment. It is deliberately clear about what that is and what it is not.
Why a point-in-time result decays
An assessment is a snapshot. It is accurate for the configuration, firmware and scope that existed at the time. Every change after that moment, whether a new extension, a firmware update, a trunk added for a new site or a rule loosened to fix a call-routing problem, moves the estate away from the tested state.
None of that is negligence. It is normal operation. The consequence is that the assurance value of a report falls steadily between assessments, and the longer the gap, the more of your live estate is running on unverified assumptions.
What changes in a telephony estate
Telephony estates are unusually prone to drift because they are operational systems that people change often. The migration away from PSTN, with Openreach targeting switch-off by 31 January 2027, is pushing many organisations onto IP-based voice on compressed timelines, which multiplies the number of changes in flight.
- New sites, numbers and SIP trunks added as the business grows.
- Firmware and platform updates that alter behaviour or reopen old settings.
- Dial-plan and permission changes made to resolve day-to-day call issues.
- Newly disclosed vulnerabilities in the underlying platform after your last test.
A critical weakness can appear without you changing anything at all. CVE-2025-57819 in FreePBX, rated CVSS 10.0 and listed in the CISA Known Exploited Vulnerabilities catalogue, is an example of a serious issue that emerges on the vendor's timeline, not yours.
An honest definition of what we mean by assurance
It would be easy to call this continuous monitoring, but that phrase implies an always-on platform watching your estate every second. GoldAgent's recurring assurance is automated and runs on a schedule, but it is not that always-on, real-time service.
Why scheduled reassessment still helps
Between a snapshot that ages for twelve months and a scheduled reassessment on a shorter cadence, the shorter cadence shrinks the window in which unverified change accumulates. You are not eliminating the gap; you are choosing how large it is allowed to grow.
Scheduled reassessment also creates a trend. Repeating the same telephony-focused checks on a set rhythm lets you see whether exposure is falling or creeping upwards, which a one-off test can never show. Human involvement means each round is validated, not just a fresh list of unconfirmed findings.
Choosing a cadence that fits the estate
The right interval depends on how fast the estate changes and what it would cost you if something were wrong. A stable estate with tight change control may be well served by an annual assessment. A fast-moving estate mid-migration, or one carrying telephone card payments, usually warrants something more frequent.
Toll fraud makes the cost of a stale picture concrete. The CFCA estimated telecom fraud losses of around US$38.95bn in 2023, and abuse of a mispermissioned dial plan can accrue cost quickly. Deciding a cadence is a judgement about acceptable exposure between rounds, and the figures here are illustrative rather than a forecast.
How to decide
Ask two questions. How often does our telephony estate actually change, and how quickly would we know if a change opened a hole? If the honest answers are often and not quickly, an annual snapshot is leaving a long unmonitored window, and a scheduled reassessment on a shorter cadence is a reasonable, proportionate response.
All GoldAgent work is carried out under written authorisation and an agreed scope, as a defensive service. The goal is simply to keep your evidence current as the estate moves, without overstating what a periodic, scheduled reassessment can do.
Sources
Related service
Continuous Assurance
Scheduled, automated reassessment with historical change tracking that keeps your exposure picture current between assessments.
Related reading
- The complete guide to SIP security
A defensive guide to SIP security for UK organisations: how the protocol works, why fraud so often starts here, trunk and registration exposure, authentication, transport security, routing and how an authorised SIP audit works.
- Automated PBX assessment vs traditional penetration testing
A fair comparison of automated PBX assessment and traditional penetration testing across repeatability, telephony focus, cost, human validation and evidence, and where each fits.
This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.