With the PSTN switch-off scheduled for 31 January 2027, telephony has become an IP system that deserves the same security scrutiny as the rest of your estate. If you are buying PBX or VoIP security testing, possibly for the first time, the market is uneven: some suppliers offer a genuine, evidence-bound assessment, and others rebrand a generic vulnerability scan. This guide sets out what a good assessment includes, how scoping and authorisation should work, what technical coverage to expect, and the questions and cost drivers that let you compare providers on substance rather than sales copy.
What a good assessment actually includes
A serious PBX and VoIP assessment does more than list open ports. It discovers your telephony footprint, identifies the platforms in use, checks them against known vulnerabilities and insecure configuration, and validates which weaknesses are genuinely exploitable. Crucially, it demonstrates the outcome that matters most in telephony: whether an attacker could place fraudulent calls at your expense.
It should finish with a prioritised, evidence-bound report, a clear severity ranking, specific remediation guidance, and a mechanism to verify fixes. If a proposal is silent on validation, on toll-fraud exposure, or on retesting, treat those silences as findings in themselves.
Scoping: define the target precisely
Scope determines both the value and the price of an assessment. A well-scoped engagement names the systems, sites, and interfaces to be examined and the depth of testing at each. Under-scoping leaves blind spots; over-scoping wastes budget on assets that carry little risk.
- Which PBX systems and how many, including any legacy platforms retained through the migration.
- How many sites, and whether remote-worker and branch connectivity are included.
- Which interfaces: SIP signalling, management interfaces, trunk and provider connectivity.
- Depth: discovery and configuration review only, or full validation including a controlled fraud proof of concept.
- Whether retesting of remediated findings is included from the outset.
Good suppliers help you scope rather than simply accepting whatever list you provide. The migration to IP telephony has left many organisations with more telephony assets than they realise, and a short scoping conversation often surfaces systems that should be in the assessment.
Technical coverage to expect
Telephony has its own attack surface, and a competent assessment covers it specifically rather than treating the PBX as a generic host. Expect coverage across signalling, the platform, authentication, management, encryption, configuration, and fraud controls.
- SIP and discovery: identifying live SIP services and responsive endpoints using standard signalling such as OPTIONS and REGISTER.
- PBX platform: vendor and version fingerprinting, then checks against known vulnerabilities and insecure defaults.
- Authentication: extension exposure and lockout-aware credential-strength testing that respects account-lockout thresholds.
- Management interfaces: review of administrative access, including the Asterisk Manager Interface where present.
- Encryption: TLS on signalling and SRTP on media, and where either is absent or misconfigured.
- Configuration: dial-plan and outbound-calling permissions assessed against least privilege, in line with NCSC guidance.
- Fraud controls: whether limits and permissions would actually contain a compromise, evidenced through a controlled proof of concept where authorised.
- Network: NAT and STUN behaviour, and passive OSINT to find exposed telephony assets.
This breadth matters because telephony flaws are consequential. Unauthenticated remote code execution issues such as CVE-2025-57819 in FreePBX, rated CVSS 10.0 and listed in the CISA Known Exploited Vulnerabilities catalogue, show that a single unpatched platform can hand an attacker control. An assessment that stops at discovery would miss the point.
Reporting standards
The report is what you are buying, so judge suppliers on it. A strong report speaks to both leadership and technical teams: a clear executive summary and prioritised findings for decision-makers, and detailed, evidenced findings with specific remediation for engineers.
Expect machine-readable outputs alongside the narrative, JSON and CSV for tracking and SARIF for pipeline ingestion, with each finding carrying a CVSS-based severity where applicable. A quantified overall risk score, expressed out of 100, and an illustrative toll-fraud exposure estimate help translate technical findings into business decisions. That estimate is directional rather than a forecast, and a good supplier will say so plainly.
- Readable HTML report with executive summary and prioritised findings.
- JSON and CSV for integration and tracking; SARIF for security and development pipelines.
- CVSS-based severity, an overall risk score out of 100, and an illustrative toll-fraud estimate.
- Specific, actionable remediation guidance per finding, with supporting evidence.
Retesting and verification
Finding a weakness is only half the job; confirming it is fixed is the other half. Retesting re-examines the specific findings you have remediated to verify the weakness is closed and that the fix did not open a new gap. It gives you defensible evidence of risk reduction rather than a list of issues you merely acknowledged.
Clarify up front whether retesting is included or priced separately, and how long after the initial assessment it is available. A supplier who treats verification as an afterthought is selling you findings, not outcomes.
Continuous versus point-in-time
A point-in-time assessment is a snapshot. It is accurate on the day and decays as firmware changes, dial plans are edited, sites are added, and new vulnerabilities are disclosed. That is not a flaw in the method; it is a property of any assessment, and it is why cadence matters.
Be wary of suppliers who market fully automated continuous monitoring for telephony without explaining what is actually automated. Our own position is deliberately honest: we do not operate a continuous monitoring platform or a customer portal. Recurring assurance is delivered as an automated, scheduled reassessment that is operationally run and human-validated, the same disciplined methodology repeated on an agreed cadence by people rather than a piece of always-on software. It is scheduled, automated reassessment that is operationally run and human-validated, and we describe it as such rather than implying automation we do not provide.
What weak assessments miss
The commonest failure is a generic vulnerability scan dressed as a telephony assessment. It reports open ports and unpatched software but never demonstrates the outcome that matters: whether fraudulent outbound calling is possible. It skips validation, so its findings are unranked and padded with false positives. And it ignores the fraud-control and dial-plan configuration where real financial risk lives.
- No validation, so findings are unconfirmed and impossible to prioritise honestly.
- No toll-fraud demonstration, so the financial risk is never made concrete.
- No dial-plan or fraud-limit review, missing the controls that contain a compromise.
- No retesting, so you never confirm anything was actually fixed.
- No hosted-PBX consent handling, exposing you to legal and scope problems.
Telephony is a direct route to money. The Communications Fraud Control Association estimated global telecom fraud losses in 2023 at around US$38.95 billion. An assessment that does not engage with fraud risk is not assessing the thing most likely to hurt you.
Questions to ask a supplier
A short list of direct questions separates substance from sales copy. Ask these and weigh the specificity of the answers.
- How do you validate findings, and how do you demonstrate toll-fraud risk without causing disruption?
- How do you obtain authorisation, and how do you handle right-party consent for a hosted PBX?
- What is your credential-testing approach, and how do you stay lockout-aware on a live system?
- Which telephony areas do you cover: SIP discovery, fingerprinting, management interfaces, encryption, dial-plan and fraud controls?
- What report formats do you provide, and do findings include CVSS severity and remediation guidance?
- Is retesting of remediated findings included, and for how long after the assessment?
- How do you deliver recurring assurance, and is it automated monitoring or scheduled reassessment?
- How do you handle PCI-relevant telephony where card data is taken by phone?
Cost drivers: what influences the price
Price varies because scope and depth vary. Understanding the drivers lets you compare quotes fairly and spot where a low price reflects a narrower, shallower engagement rather than better value.
- Number of assets and systems: more PBX platforms and endpoints mean more to discover, fingerprint, and test.
- Number of sites: multi-site and remote-worker connectivity widen the footprint.
- Scope breadth: signalling only, or full coverage across management, encryption, and fraud controls.
- Depth: configuration review versus full validation with a controlled toll-fraud proof of concept.
- Retesting: whether verification of fixes is included or priced separately.
- Frequency: a one-off assessment versus a periodic reassessment cadence.
- Context: PCI-relevant or otherwise regulated environments require more careful scoping and evidence.
A quote that is markedly cheaper than others usually reflects less depth: no validation, no fraud demonstration, no retesting. That may be acceptable for a low-risk system, but compare like for like before deciding.
How to compare providers
Compare on substance. Two proposals at similar prices can differ enormously in what they actually do. Line them up against a consistent checklist and the differences become obvious.
- Do they validate findings and demonstrate toll-fraud risk, or only scan and list?
- Do they handle authorisation and hosted-PBX consent properly?
- Is their technical coverage telephony-specific and complete?
- Are report formats and severity scoring fit for both leadership and engineers?
- Is retesting included, and is their assurance model described honestly?
- Do they understand your regulatory context, including PCI where card data is taken by phone?
The best provider is not the cheapest or the one with the most polished deck. It is the one whose method you can see, whose claims are honest about what is automated and what is human, and whose report you could hand to both your board and your engineers with confidence. As telephony completes its move to IP ahead of the 2027 switch-off, that clarity is what you are really buying.
Sources
Related service
PBX Security Assessment
An authorised, end-to-end assessment of the PBX systems your business runs on.
Related reading
- Cloud PBX vs on-premises PBX: the security differences
A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.
- How a PBX security assessment works, step by step
A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.
- Automated PBX assessment vs traditional penetration testing
A fair comparison of automated PBX assessment and traditional penetration testing across repeatability, telephony focus, cost, human validation and evidence, and where each fits.
- PBX security assessment vs vulnerability scanning
How a telephony-focused PBX security assessment differs from generic vulnerability scanning on context, validation, toll-fraud demonstration and dial-plan review.
This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.