Skip to content

NCSC PBX security guidance: a practical checklist

A practical checklist drawn from the NCSC's PBX best-practice guidance, with the official source linked and notes on where an authorised assessment helps you evaluate the controls.

7 min readPublished 14 August 2026By Rocco Clayfield

The NCSC publishes clear best-practice guidance for securing a private branch exchange, and it is the right starting point for anyone responsible for a phone system. This article summarises that guidance as a practical checklist and links the official document so you can read it in full. It is a self-help guide, and nothing here implies the NCSC endorses any commercial service, including GoldAgent's.

Start with the official guidance

Before working through any checklist, read the NCSC's own Private Branch Exchange best-practice publication, linked in the sources below. It is the authoritative reference, and this article is a summary intended to make it easier to act on, not a replacement for it.

Access and authentication

A large share of PBX compromise comes down to weak or default access. The guidance points towards removing default credentials, enforcing strong authentication and restricting who can reach administrative functions.

  • Change all default usernames and passwords before a system goes live.
  • Use strong, unique credentials for administrative and voicemail accounts.
  • Restrict management interfaces to trusted networks rather than exposing them openly.
  • Review who holds administrative access and remove accounts that are no longer needed.

An authorised assessment helps here by checking whether these controls hold in the live configuration rather than only on paper, including whether management interfaces are genuinely restricted.

Call routing and toll-fraud controls

The guidance places weight on controlling outbound calling, because permissive routing is what turns a compromise into a bill. The aim is to allow only the call types the business actually needs.

  • Bar international and premium-rate destinations unless there is a clear business need.
  • Apply call barring and time-of-day limits to reduce out-of-hours abuse.
  • Secure voicemail so it cannot be used to make onward or international calls.
  • Set credit limits or alerts with your provider where these are available.

Toll fraud remains a live financial threat; the CFCA estimated telecom fraud losses of around US$38.95bn in 2023. An assessment can review the dial plan and, where authorised, demonstrate whether a route that should be barred can in fact be used.

Patching and maintenance

Keeping the platform current is a core theme of the guidance. Telephony software carries serious vulnerabilities like any other, and they are exploited in the wild.

CVE-2025-57819 in FreePBX, rated CVSS 10.0 and listed in the CISA Known Exploited Vulnerabilities catalogue, shows why timely updates and a known inventory of versions matter. An assessment helps confirm what you are running and whether known issues are actually reachable in your setup.

Monitoring, logging and call records

The guidance encourages keeping and reviewing logs and call detail records so that abuse can be spotted. Unusual patterns, such as a spike in international calls at night, are often the first visible sign of fraud.

  • Enable logging on the PBX and retain call detail records.
  • Review records for unusual destinations, volumes or times.
  • Make sure someone is responsible for looking at alerts, not just collecting them.

An assessment can check whether the records you need are actually being produced and are complete enough to be useful, which is easy to assume and worth verifying.

Migration and payment considerations

Many organisations are moving to IP-based voice ahead of the Openreach PSTN switch-off, targeted for 31 January 2027. Migration is exactly when configurations change quickly and controls can be lost, so it is a sensible moment to check the estate against this checklist.

If you take card payments by phone, add the PCI guidance on telephone-based payment card data to your reading. The telephony layer then sits inside your cardholder data environment, and the controls above carry extra weight.

Where an authorised assessment fits

This checklist tells you what good looks like. An authorised assessment tells you whether your estate meets it in practice. The two work together: the guidance sets the controls, and independent testing evaluates whether they are actually in place and effective.

GoldAgent's assessments are telephony-specific and carried out only under written authorisation and an agreed scope, as a defensive service. They are a way to evaluate your estate against best-practice controls such as these, and are not a claim of official endorsement by anyone.

Sources

Related service

PBX Security Assessment

An authorised, end-to-end assessment of the PBX systems your business runs on.

Related reading

  • Cloud PBX vs on-premises PBX: the security differences

    A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.

  • How a PBX security assessment works, step by step

    A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.

  • The 2026 buyer's guide to PBX and VoIP security testing

    A comprehensive buyer's guide to commissioning PBX and VoIP security testing in 2026: what a good assessment includes, scoping and authorisation, technical coverage, reporting standards, retesting, cost drivers, and how to compare suppliers.

  • Automated PBX assessment vs traditional penetration testing

    A fair comparison of automated PBX assessment and traditional penetration testing across repeatability, telephony focus, cost, human validation and evidence, and where each fits.

This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.