Skip to content

PBX security assessment vs vulnerability scanning

How a telephony-focused PBX security assessment differs from generic vulnerability scanning on context, validation, toll-fraud demonstration and dial-plan review.

7 min readPublished 14 August 2026By Rocco Clayfield

Vulnerability scanning is a genuinely useful control, and this article is not an argument against it. The point is narrower: a generic scanner and a telephony-focused assessment answer different questions, and confusing the two leaves phone-system risk poorly understood. Below is a fair account of what a scanner gives you, where it stops, and what an assessment adds.

What a scanner does well

A vulnerability scanner is fast, broad and repeatable. It checks assets against a large database of known issues and produces a list, often with severity scores, in a fraction of the time a human would take. For maintaining hygiene across a wide estate and catching known, unpatched software, it is hard to beat on coverage per pound.

Used well, scanning is a sensible first layer. It will reliably tell you when a platform is running a version associated with a published vulnerability, which is valuable information in its own right.

Where generic scanning stops

A generic scanner reports issues without telephony context. It can tell you a SIP service is present and possibly which version, but it does not understand whether your dial plan permits international routing that should be blocked, or whether a trunk will accept calls it should reject.

It also lists rather than validates. A finding may be a false positive in your configuration, or the truly dangerous problem may be a combination of settings that no single signature captures. A score in a report is not the same as a confirmed, exploitable path.

  • No dial-plan review: it does not read how calls are permitted and routed.
  • No toll-fraud demonstration: it will not show that fraudulent calls can actually be placed.
  • Limited validation: findings are flagged, not confirmed against your live configuration.
  • Little business framing: severity is generic, not tied to what a call would cost you.

What an assessment adds

A PBX security assessment starts from how the telephony platform is meant to behave and tests against that. It includes reviewing the dial plan and call permissions, checking SIP registration and trunk authentication, and examining management interfaces and international routing for abuse potential.

Crucially, it validates. Where a weakness is found, an assessor confirms whether it is real and, where safe and authorised, demonstrates the impact, for example that a call could be placed through a route that should not permit it. That demonstration is what makes toll-fraud risk tangible rather than theoretical.

Why telephony context matters

Toll fraud is a direct financial attack that does not need a foothold on your wider network. The CFCA estimated telecom fraud losses of around US$38.95bn in 2023. A scanner that misses a permissive dial plan misses exactly the weakness an attacker would monetise.

Platform-specific severity also needs interpretation. CVE-2025-57819 in FreePBX carried a CVSS score of 10.0 and appears in the CISA Known Exploited Vulnerabilities catalogue, but whether your instance is exposed depends on configuration and reachability that only assessment confirms.

Where payments raise the stakes

If you take card payments over the phone, the telephony layer sits inside your cardholder data environment. PCI guidance on telephone-based payment card data sets out expectations that a generic scan does not evaluate, such as how call recording, routing and agent environments are controlled.

Here the gap between listing and validating is not academic. An unvalidated scan may satisfy nobody in an audit, whereas a telephony assessment can evidence how the relevant controls behave in practice.

Use both, for what each does

The honest conclusion is that these are complementary. Keep scanning for broad, frequent hygiene across the estate. Use a telephony-focused assessment to understand, validate and evidence the phone-system risks that a generic tool is not built to see.

GoldAgent's assessments are telephony-specific and carried out only under written authorisation and an agreed scope. They are a defensive service designed to add the context, validation and evidence that scanning alone does not provide.

Sources

Related service

PBX Security Assessment

An authorised, end-to-end assessment of the PBX systems your business runs on.

Related reading

  • Cloud PBX vs on-premises PBX: the security differences

    A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.

  • How a PBX security assessment works, step by step

    A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.

  • The 2026 buyer's guide to PBX and VoIP security testing

    A comprehensive buyer's guide to commissioning PBX and VoIP security testing in 2026: what a good assessment includes, scoping and authorisation, technical coverage, reporting standards, retesting, cost drivers, and how to compare suppliers.

  • Automated PBX assessment vs traditional penetration testing

    A fair comparison of automated PBX assessment and traditional penetration testing across repeatability, telephony focus, cost, human validation and evidence, and where each fits.

This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.