Authorised assessment
SIP Security Audit
A focused audit of the SIP layer: trunks, registration, authentication and signalling exposure, where a large share of telephony fraud and interception begins.
This is active, authorised testing. We confirm scope and written authorisation before any active work begins, including a hosted provider's consent where required.
The problem
SIP is where telephony fraud usually starts
SIP trunks and registrations are frequently exposed to the internet with weak authentication and permissive configuration. Attackers scan for them continuously, because a single compromised SIP account can be turned into fraudulent call spend within hours.
What we commonly find
- SIP services reachable from any address on the internet
- Weak or guessable registration and trunk credentials
- No rate limiting or lockout on registration attempts
- Permissive routing that allows unexpected call paths
- Signalling exposure that reveals internal detail
The approach
Audit the SIP layer specifically
GoldAgent assesses the SIP layer in detail: how trunks and registrations are exposed, how authentication holds up, and how routing is configured. You get evidenced, prioritised fixes.
- Trunk and registration exposure mapped and assessed
- Authentication strength and lockout behaviour reviewed
- Routing and dial-plan permissiveness examined
- Findings validated and prioritised for remediation
Scope
What is in, and what is out
In scope
- The SIP services, trunks and registrations listed in the written authorisation
- Authentication, registration handling and lockout behaviour on those services
- Routing and dial-plan permissiveness that is visible under authorisation
- How the SIP layer is presented on the public internet, within scope
Out of scope
- Carrier core networks you do not control
- Trunks not named in the written scope
- Placing billable fraudulent calls, including live premium-rate proofs
- The provider's platform without that provider's consent
The written authorisation is the source of truth. If a system is not named, it is not tested.
Methodology
How the engagement runs
- 1
Define scope
Agree the SIP services, trunks and registrations in and out of scope.
- 2
Confirm authorisation
Written confirmation of ownership or right-to-test, including provider consent where required.
- 3
Discover exposure
Identify reachable SIP services and how they are presented.
- 4
Analyse posture
Assess authentication, registration handling and routing configuration.
- 5
Validate findings
Confirm each issue is real and reproducible.
- 6
Prioritise risk
Rank by severity, exploitability and business impact.
- 7
Deliver the report
Management summary plus technical findings and remediation.
- 8
Retest
Confirm remediated findings and update status.
What you receive
- Executive summary
- SIP exposure inventory
- Findings with severity and evidence
- Authentication and routing assessment
- Prioritised remediation guidance
- Retest status
Who it suits
- Businesses using SIP trunks for inbound and outbound calls
- Organisations with self-managed SIP infrastructure
- VoIP resellers and MSPs assuring customer SIP services
Risks it addresses
Fraudulent call spend
A compromised SIP account is commonly used to place expensive international or premium-rate calls.
Service abuse
Open or weakly authenticated SIP services are abused for relaying and interception.
FAQ
SIP Security Audit: questions
We use a provider's SIP trunks. Can you still help?
Yes. We assess the exposure on your side of the trunk and, where the provider's consent is required, confirm it before active work begins.
Will you attempt live fraudulent calls?
No. Any proof-of-concept work is run in a controlled, non-billable manner by default and only with your explicit agreement.
What is in scope, and what is not?
In scope are the SIP services, trunks and registrations you authorise in writing, including authentication, registration handling and routing that is visible on those systems. Out of scope are unnamed trunks, carrier core networks, the provider's platform without consent, and placing billable fraudulent calls.
How is this different from a generic penetration test?
A general test often stops at an open port. This audit examines how trunks authenticate, how registration is limited, and whether routing would allow unexpected call paths, with each finding validated by a person.
What do you need from us before work starts?
A written list of SIP services and trunks, confirmation of ownership or right-to-test, and provider consent where a hosted trunk requires it.
How is the price set?
Assess starts from £800. Assure, the flagship, starts from £1,290 per year. Quotes follow scoping. Any pound figure for fraud exposure is an illustrative scenario, not a forecast.
Can MSPs white-label a SIP audit?
Yes. GoldAgent Partner can deliver the SIP audit under your brand where commercially agreed. Referral is available if you would rather introduce us than resell.
Related services
Explore related assessments
PBX Security Assessment
An authorised, end-to-end assessment of the PBX systems your business runs on.
Read moreVoIP Security Assessment
An attack-surface review of your VoIP platform, endpoints and remote users.
Read moreToll-Fraud Risk Assessment
Find the exposure that lets attackers turn your phone system into call spend.
Read more
Request a SIP Security Audit
We confirm scope and authorisation first, then show you exactly what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.