Skip to content

Authorised assessment

PBX Security Assessment

A structured, authorised assessment of your PBX estate that shows exactly what is exposed, how an attacker would use it, and what to fix first.

This is active, authorised testing. We confirm scope and written authorisation before any active work begins, including a hosted provider's consent where required.

The problem

Phone systems are rarely tested, and attackers know it

PBX platforms sit outside most vulnerability-management programmes. They are installed once, connected to the internet for remote administration or SIP trunking, and then left. Configuration drifts, extensions accumulate, and firmware ages while nobody is watching the telephony layer.

What we commonly find

  • Management interfaces reachable from the public internet
  • Default or weak credentials on administrative and SIP accounts
  • Forgotten extensions and test accounts that were never disabled
  • Outbound dialling permissions wider than the business needs
  • Firmware and application versions with known, published vulnerabilities
  • No logging or alerting on the systems that carry every call

The approach

A specialist assessment built for telephony

GoldAgent combines deep PBX and SIP knowledge with a repeatable assessment engine and human validation. We map what is exposed, confirm which weaknesses are real, and rank them by the business risk they carry, not by raw scanner output.

  • Telephony-specific checks a generalist scanner does not run
  • Every finding validated by a person before it reaches your report
  • Risk prioritised by exploitability and business impact
  • Clear, evidenced remediation guidance your team can act on
  • A defined retest path to confirm the fixes worked

Scope

What is in, and what is out

In scope

  • The PBX hosts, management interfaces and SIP services listed in the written authorisation
  • Authentication and account hygiene on those in-scope systems
  • Dial-plan and outbound routing as configured
  • Firmware and application version posture of the assessed platform
  • Logging and fraud-relevant controls that are visible during the assessment

Out of scope

  • Systems not named in the written scope
  • Hosted platforms without the provider's consent where that consent is required
  • Social engineering of staff
  • Placing billable fraudulent calls
  • Always-on monitoring or a customer portal

The written authorisation is the source of truth. If a system is not named, it is not tested.

Methodology

How the engagement runs

  1. 1

    Define scope

    Agree the exact systems, addresses and services in scope, and the systems explicitly out of scope.

  2. 2

    Confirm authorisation

    You confirm ownership or right-to-test in writing before any active work begins. Hosted systems need the provider's consent where required.

  3. 3

    Discover exposure

    Identify the PBX, SIP and management services reachable within the agreed scope.

  4. 4

    Analyse posture

    Assess configuration, authentication, versioning and dialling controls against known telephony attack paths.

  5. 5

    Validate findings

    Confirm each issue is real and reproducible, removing false positives before reporting.

  6. 6

    Prioritise risk

    Rank findings by severity, exploitability and business impact.

  7. 7

    Deliver the report

    A management summary plus technical detail, evidence and remediation guidance.

  8. 8

    Retest

    Re-check remediated findings and update their status.

What you receive

  • Executive summary written for decision-makers
  • Technical findings with severity ratings
  • Evidence for each finding and the affected service
  • Prioritised, actionable remediation guidance
  • An exposure inventory of the tested estate
  • Retest status once fixes are applied

Who it suits

  • Organisations running on-premises or hosted PBX systems
  • Businesses with legacy telephony that has never been assessed
  • IT teams preparing evidence for an insurance renewal or a security questionnaire
  • Companies taking card payments by phone (PCI DSS scope)

Risks it addresses

  • Toll fraud

    Compromised extensions and permissive dial plans let attackers place expensive calls the business is usually liable for.

  • Call interception

    Weak segmentation and authentication can expose call content and signalling.

  • Service disruption

    An exposed, unpatched PBX is a single point of failure for every inbound and outbound call.

FAQ

PBX Security Assessment: questions

Will testing disrupt our live phones?

The assessment is planned around your environment, with lockout-aware techniques and an agreed emergency-stop contact. Higher-impact tests are only run with your explicit agreement.

Do you test hosted PBX systems?

Yes, where the party with authority over the hosted system authorises it. Where a provider's consent is required, that is confirmed before active work begins.

How long does an assessment take?

A single-site PBX assessment is typically completed within a few working days from the point scope and authorisation are confirmed. Larger estates are scoped individually.

What do we get at the end?

A management-ready report with an executive summary, evidenced technical findings, severity ratings and prioritised remediation guidance, followed by a retest of the fixes.

What is in scope, and what is not?

In scope are the PBX hosts, management interfaces, SIP services, authentication, dial-plan and firmware posture you list in the written authorisation. Out of scope are unnamed systems, hosted platforms without the provider's consent where it is required, social engineering of staff, and placing billable fraudulent calls.

How is this different from a generic penetration test?

A general network test rarely covers SIP registration, dial-plan permissiveness, extension hygiene or toll-fraud paths in depth. This assessment is built for that layer, with findings validated by a person and ranked by business impact.

What do you need from us before work starts?

A written scope, confirmation that you own the systems or have the right to have them tested, and, for hosted platforms, the provider's consent where required. An emergency-stop contact is agreed before active work.

How is the price set?

GoldAgent Assess starts from £800. The figure depends on estate size and systems in scope. Assure, the flagship annual programme, starts from £1,290. A confirmed quote follows scoping. Any toll-fraud pound figure in the report is an illustrative scenario, not a forecast.

What happens if you find a critical issue during the assessment?

We tell your agreed emergency-stop contact promptly, with enough detail to act. The finding still appears in the report with evidence and remediation. We do not disclose it to anyone else.

Can MSPs resell or white-label this?

Yes. GoldAgent Partner is white-label telephony security for MSPs and providers: reporting under your brand where commercially agreed, or a straightforward referral model if you prefer not to resell.

Related services

Explore related assessments

Request a PBX Security Assessment

We confirm scope and authorisation first, then show you exactly what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.