Skip to content

Authorised assessment

VoIP Security Assessment

A focused assessment of your VoIP platform: the servers, endpoints, remote users and services that carry your calls, and the exposure an attacker could reach.

This is active, authorised testing. We confirm scope and written authorisation before any active work begins, including a hosted provider's consent where required.

The problem

VoIP widened the attack surface and moved it off-site

Cloud and hybrid VoIP put telephony on the same networks as everything else, and pushed endpoints into homes and branch offices. That flexibility also created remote administration paths, exposed signalling and endpoints that are rarely patched or monitored.

What we commonly find

  • Externally reachable VoIP management and provisioning services
  • Remote and home-worker endpoints outside the corporate perimeter
  • Weak or reused credentials across accounts and devices
  • Signalling and media exposure from misconfiguration
  • Provisioning systems that leak configuration or credentials

The approach

Assess the whole VoIP attack surface, not just the server

GoldAgent looks at the platform, the endpoints and the remote-access paths together, so you see the exposure the way an attacker would, end to end, with each finding validated and prioritised.

  • Platform, endpoint and remote-access exposure assessed together
  • Provisioning and configuration exposure specifically checked
  • Findings validated and de-duplicated before reporting
  • Remediation guidance tuned to hosted, on-premises or hybrid setups

Scope

What is in, and what is out

In scope

  • The VoIP platform, endpoints and remote-access paths listed in the written authorisation
  • Provisioning and configuration exposure on those paths
  • Authentication and signalling posture within scope
  • Endpoint firmware and registration hygiene where reachable under authorisation

Out of scope

  • Endpoints and sites not named in scope
  • The hosted provider's core platform without that provider's consent
  • Physical handset theft or staff social engineering
  • Placing billable fraudulent calls

The written authorisation is the source of truth. If a system is not named, it is not tested.

Methodology

How the engagement runs

  1. 1

    Define scope

    Agree platform, endpoints, remote-access paths and provisioning services in and out of scope.

  2. 2

    Confirm authorisation

    Written confirmation of ownership or right-to-test, including any provider consent required.

  3. 3

    Discover exposure

    Map the reachable VoIP services, endpoints and provisioning paths.

  4. 4

    Analyse posture

    Assess authentication, signalling exposure, provisioning and endpoint configuration.

  5. 5

    Validate findings

    Confirm each issue is real, removing noise before reporting.

  6. 6

    Prioritise risk

    Rank by severity, exploitability and business impact.

  7. 7

    Deliver the report

    Management summary plus technical findings, evidence and remediation.

  8. 8

    Retest

    Confirm remediated findings and update status.

What you receive

  • Executive summary for decision-makers
  • VoIP attack-surface inventory
  • Technical findings with severity and evidence
  • Endpoint and provisioning exposure detail
  • Prioritised remediation guidance
  • Retest status once fixes are applied

Who it suits

  • Organisations on cloud, hosted or hybrid VoIP
  • Businesses with significant remote or home-worker telephony
  • IT teams migrating from legacy PBX to VoIP
  • MSPs assuring VoIP estates for their customers

Risks it addresses

  • Remote endpoint compromise

    Unmanaged, exposed endpoints are an easy foothold into the voice estate.

  • Credential theft

    Leaked provisioning data and weak accounts enable fraud and interception.

  • Toll fraud

    Compromised VoIP accounts are routinely used to generate fraudulent call spend.

FAQ

VoIP Security Assessment: questions

Do you assess remote and home-worker endpoints?

Yes, within the agreed scope. Remote endpoints are a common exposure point and are assessed as part of the attack surface.

Can you work with our hosted VoIP provider's platform?

Where the party with authority authorises testing and any provider consent is in place, yes. We confirm this before active work begins.

Is this different from a PBX assessment?

It overlaps but focuses on the VoIP platform, endpoints and remote-access paths. Many estates benefit from both; we scope to your environment.

What is in scope, and what is not?

In scope are the platform, endpoints, remote-access and provisioning paths you authorise in writing. Out of scope are unnamed sites, a hosted provider's core platform without consent, social engineering, and placing billable fraudulent calls.

How is this different from a generic penetration test?

A general test rarely examines VoIP provisioning, endpoint registration or signalling exposure in depth. This assessment is built for that surface, with findings validated by a person.

What do you need from us before work starts?

A written scope, confirmation of ownership or right-to-test, and provider consent where a hosted platform requires it. Remote endpoints are included only when they are in that scope.

How is the price set?

Assess starts from £800. Assure, the flagship annual programme, starts from £1,290. Quotes follow scoping. Any pound figure for fraud exposure is an illustrative scenario, not a forecast.

Can our MSP commission this under their brand?

Yes. GoldAgent Partner white-labels VoIP assessment reporting for MSPs and resellers where commercially agreed, so your customer relationship stays yours.

Related services

Explore related assessments

  • PBX Security Assessment

    An authorised, end-to-end assessment of the PBX systems your business runs on.

    Read more
  • SIP Security Audit

    A focused review of SIP trunks, registration and authentication.

    Read more
  • Continuous Assurance

    Scheduled, automated reassessment with historical change tracking that keeps your exposure picture current between assessments.

    Read more

Request a VoIP Security Assessment

We confirm scope and authorisation first, then show you exactly what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.