Skip to content
Breakpoint Labs
Authorised systems only. Breakpoint Labs works only on authorised scope, so rules of engagement are agreed in writing first.

Coverage note

VoIP penetration testing for business phone systems

VoIP penetration testing checks the systems behind your business telephony. So it covers call servers, admin access, trunks and how voice traffic is separated from the rest of the network.

  • Manual exploit chains
  • PTES and the OWASP testing guide
  • Authorised scope only
Voip penetration testing: agree the scope, test with authorisation and evidence and retest

Why voip penetration testing matters

Phone systems run on the same networks as everything else now. Therefore a weak call server can become a foothold, and toll fraud can cost real money quickly.

Telephony is often managed by a separate team or provider. Also, admin portals for phone systems are easy to forget during wider testing.

What voip penetration testing covers

The test covers the platform and its surroundings. For example, whether a desk phone network can reach business servers.

  • Call server and admin portal security
  • Trunk and provider connections
  • Voice network separation
  • Voicemail and user portal access
  • Logging and fraud monitoring

Voip penetration testing readiness check

Tick what is already true. Open items go into the written rules of engagement.

Your result appears here as you tick, so you can see what is still open.

Scoping voip penetration testing

Platform type drives scope. However, provider agreements may set limits.

QuestionEffect on scope
On-premises or hosted?Hosted platforms limit scope
How many sites?Each site's network is checked
Contact centre in scope?Adds systems
Provider involved?Their rules apply

Authorisation and safety

Testing runs only under written rules of engagement, and the provider's terms are checked first. Also, testing never disrupts emergency calling.

In addition, no calls are placed to outside numbers without agreement. As a result, nothing affects customers or costs.

Evidence, fees and retest

Findings come with evidence and a fix, following NIST SP 800-115.

Full engagements run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Attack Surface Diagnostic starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.

Also review provider access. Because many phone systems are supported remotely by a provider, their access path deserves the same scrutiny as your own. So confirm how they connect and who approves it. In addition, set spending alerts on trunks, because fraud shows up quickly in call costs.

Voip penetration testing questions

Does VoIP penetration testing affect calls?

It is planned to avoid disruption, and emergency calling is never touched.

Can VoIP penetration testing cover a hosted platform?

Your configuration and portals, within the provider's terms.

What does VoIP penetration testing usually find?

Weak admin access and poor separation of voice networks.

Who leads the work?

A senior penetration hacker.

Related guides

Send the brief for voip penetration testing

Describe your phone platform and sites. The penetration hacker who would lead the work replies with a written scope and one fixed fee.

Send the brief