Skip to content

How to secure a business PBX: a practical review

A defensive, step-by-step way to review a business phone system (exposure, accounts, dialling, patching and monitoring), written for IT teams.

8 min readPublished 14 August 2026By Rocco Clayfield

Most business phone systems are installed once and then left. This guide sets out a practical way to review a PBX defensively, in the order that reduces the most risk first. It does not describe how to attack a system; it describes what to check on your own.

Why the phone system gets overlooked

Telephony rarely sits inside a vulnerability-management programme. It is treated as infrastructure that works until it doesn't, connected to the internet for remote administration or SIP trunking, and then forgotten. Configuration drifts, extensions accumulate and firmware ages while nobody is looking at the telephony layer specifically.

The result is that a PBX often carries exposure that would never be tolerated on a web server: management interfaces on the public internet, default credentials, and dialling permissions far wider than the business needs.

Start with external exposure

The single highest-value question is: what of your phone system is reachable from the internet? Attackers scan continuously for exposed SIP and management services, because a reachable service is the start of every remote compromise.

  • Identify which telephony services are reachable from outside your network.
  • Confirm whether management and administration interfaces are exposed; they rarely need to be.
  • Check that remote administration, where genuinely needed, is restricted to known addresses or a VPN.
  • Remove or firewall anything exposed that does not need to be.

Accounts and authentication

Weak and forgotten accounts are the most common way telephony gets compromised. Every extension, SIP account and administrative login is a credential an attacker can try.

  • Change every default credential on the PBX, endpoints and management tools.
  • Enforce strong, unique passwords on administrative and SIP accounts.
  • Enable multi-factor authentication anywhere the platform supports it.
  • Disable unused extensions, test accounts and departed-staff logins.
  • Ensure registration and login attempts are rate-limited and locked out after repeated failures.

Dialling permissions and fraud

Toll fraud depends on a compromised account being able to place expensive calls. Tightening what each account is allowed to dial removes most of the value of a compromise.

  • Restrict international and premium-rate dialling to the accounts that genuinely need it.
  • Disable call routes the business never uses.
  • Set out-of-hours and volume limits where the platform allows.
  • Turn on alerting for unusual calling patterns, so fraud is caught in hours, not on the next bill.

Patching, logging and monitoring

PBX and VoIP vendors publish vulnerabilities regularly. An unpatched, exposed platform with no logging is both an easy target and a blind spot.

  • Track firmware and application versions against the vendor's published advisories.
  • Apply security updates on a defined cycle, not ad hoc.
  • Enable logging on the systems that carry your calls, and make sure someone reviews it.
  • Alert on administrative changes and unusual registration or calling activity.

When to bring in an assessment

A self-review closes obvious gaps. An independent, authorised assessment confirms what is actually exposed, validates which weaknesses are real, and prioritises them by business risk: the evidence insurers, auditors and boards increasingly expect.

It is worth doing after a migration, before a Cyber Essentials or insurance renewal, when you take card payments by phone, or simply when the phone system has never been assessed.

Related service

PBX Security Assessment

An authorised, end-to-end assessment of the PBX systems your business runs on.

Related reading

  • The complete guide to PBX security

    A defensive, UK-focused guide to securing a modern PBX: external exposure, authentication, management interfaces, dial-plan design, patching, encryption, logging and independent assessment against NCSC guidance.

  • Cloud PBX vs on-premises PBX: the security differences

    A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.

  • How a PBX security assessment works, step by step

    A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.

  • The 2026 buyer's guide to PBX and VoIP security testing

    A comprehensive buyer's guide to commissioning PBX and VoIP security testing in 2026: what a good assessment includes, scoping and authorisation, technical coverage, reporting standards, retesting, cost drivers, and how to compare suppliers.

This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.