Business VoIP

VoIP Security: How to Protect Your Business Calls from Attack

VoIP phone systems face specific security threats — including call interception, toll fraud, and phishing through voice calls (vishing). This guide explains the most significant VoIP security risks facing UK businesses and the practical controls that reduce them.

VoIP Security: Why It Matters

Toll fraud, call interception, and vishing are the primary VoIP security threats for UK businesses. Toll fraud alone can generate losses of thousands of pounds within hours of a system being compromised. AMVIA deploys SRTP/TLS encryption, SIP hardening, and real-time fraud detection as standard on all managed VoIP deployments.

Explore VoIP security options

Most UK businesses moving off the old phone network treat the switch to VoIP as a telecoms decision. It is a security decision. A voice system reachable over the internet is a server reachable over the internet — and attackers scan for it around the clock. This page sits under our business VoIP pillar and explains the threats, the controls, and where managed cybersecurity cover the gaps a typical installer leaves open.

Why does VoIP security matter for UK businesses?

VoIP is attacked because it offers something most cyberattacks do not: direct, immediate financial payoff. The Communications Fraud Control Association estimates global telecommunications fraud costs the industry around $38–40 billion annually (CFCA survey, market estimate as of 2026), with toll fraud a significant share. The UK's migration off the old PSTN network, due to complete by 31 January 2027, is widening the attack surface as more firms expose voice systems to the public internet.

The risk is concentrated and fast. Unlike a slow data breach, a compromised phone system bleeds money in hours, usually overnight or across a weekend when no one is watching the call logs.

  • Toll fraud turns your phone system into someone else's revenue stream
  • SIP scanners probe internet-facing systems continuously, not occasionally
  • Unencrypted calls can be captured on shared or poorly segmented networks
  • Voice phishing targets your staff, not your switchboard

What are the main VoIP security threats?

The four threats that matter for UK SMEs are toll fraud, SIP scanning, call interception and vishing. Each has a clear technical control and, in the case of vishing, a human one. Treating them together — voice plus the wider security stack — is what separates a managed service from a phone install.

How does toll fraud work, and how do you stop it?

Toll fraud (international revenue share fraud) happens when attackers gain VoIP access through brute-force attacks, credential stuffing or default-password exploitation, then place large volumes of calls to premium-rate international destinations they profit from. "An undetected attack running for 48 hours over a weekend...can generate bills of tens of thousands of pounds." Single weekend attacks producing losses above £50,000 have been documented in UK cases (typical 2026 range).

Prevention requires layered controls:

  • Strong, unique passwords on every SIP account
  • Failed-authentication alerting with automatic lockout
  • Blocking calls to high-risk international destinations by default
  • Daily and weekly spend limits with automatic cut-offs
  • Real-time monitoring for unusual call patterns, not month-end invoice review

What is SIP scanning, and how is it blocked?

SIP scanning is the automated probing of internet-facing IP addresses to find VoIP systems and test default credentials. Tools such as SIPVicious are freely available, so this is constant background noise on any exposed system. Protection means never exposing SIP ports directly to the public internet, enforcing strong non-default passwords of at least 16 characters, configuring fail2ban-equivalent brute-force protection, and restricting SIP registration to known IP ranges.

Can business calls be intercepted or overheard?

Yes. Unencrypted VoIP calls can be captured on shared network segments — a real risk for businesses using shared or public Wi-Fi, poorly segmented guest networks, or already-compromised internal networks. The fix is to enable SRTP, which encrypts the voice content, and TLS, which encrypts the SIP signalling, on every business VoIP system. Treat an unencrypted call the same way you would treat a plain-text password.

How does vishing target your staff?

Vishing — voice phishing — uses phone calls to manipulate staff into disclosing credentials, authorising payments or granting system access, with attackers impersonating HMRC, banks, IT support, couriers or senior management. STIR/SHAKEN caller authentication and call filtering block many spoofed numbers, but the decisive control is human. As the NCSC's phishing guidance makes clear, staff awareness is a primary defence: legitimate IT, banks and HMRC never request passwords on unsolicited calls. Our anti-phishing and managed cybersecurity services cover this training alongside the technical filtering.

What does a session border controller do for VoIP security?

A session border controller (SBC) is a network device that sits at the boundary between your internal VoIP network and the public internet. It hides internal VoIP topology from external probing, enforces access control on SIP traffic, defends against SIP-based denial-of-service attacks, handles NAT traversal, and enforces encryption policy.

For any deployment involving SIP trunking or Direct Routing to platforms such as Microsoft Teams, an SBC should be treated as essential infrastructure rather than optional. If you are connecting a hosted phone system to the wider internet, the SBC is the front door — and it should be locked.

Denial-of-service attacks against VoIP infrastructure overwhelm SIP services or your internet connection with malicious traffic, potentially taking the phone system fully offline. SBC-level rate limiting, firewall rules restricting SIP to known sources, bandwidth management and disaster-recovery call routing to mobiles or alternative sites keep calls flowing under attack.

In-house DIY versus AMVIA managed VoIP security

A phone installer configures call routing. A security partner configures defences. The difference shows up the first time someone scans your system at 2am on a Saturday.

VoIP security controlTypical DIY / installer setupAMVIA managed VoIP security
SIP authenticationDefault or weak passwordsStrong unique credentials, brute-force lockout
Call encryptionOften left offSRTP + TLS enforced on every endpoint
Toll-fraud detectionSpotted on the next invoiceReal-time alerts and automatic blocks
Internet exposureSIP port open to the worldSBC and firewall restrict to known sources
Vishing defenceNoneStaff awareness training + call filtering
MonitoringNoneContinuous, tied to the wider security stack

What are the VoIP security best practices for UK SMEs?

The baseline below closes the gaps attackers exploit most. None of it is exotic; the failure is almost always that no one owns it. That ownership is the point of a managed service.

  • Change all default SIP passwords immediately — at least 16 characters mixing letters, numbers and symbols
  • Enable SRTP and TLS on your VoIP platform — unencrypted voice is plain-text risk
  • Deploy a session border controller — never expose a PBX/VoIP SIP interface directly to the internet
  • Set international call limits and spend caps with alerts and automatic blocks
  • Implement real-time fraud monitoring rather than waiting for the monthly bill
  • Segment your voice network onto a separate VLAN from general data traffic
  • Train finance, reception and PA staff on vishing at regular intervals
  • Patch VoIP firmware and software with the same discipline as servers and workstations

Ofcom's guidance on the PSTN switch-off is a useful reference point for planning the move, but the switch is the moment to get these controls in place — not after the first fraudulent bill.

How does AMVIA secure business VoIP?

AMVIA delivers VoIP security as part of one accountable managed service, not a bolt-on. We harden SIP authentication, enforce encrypted call transport, deploy and manage the SBC, and run continuous toll-fraud detection — then connect it all to the same security operations that protect your Microsoft 365 and endpoints. One provider, security-first, Microsoft-certified engineers.

That single-provider model matters: when voice, network and identity are watched together, an unusual call pattern is read in context rather than in isolation. For most SMEs that is the difference between catching fraud in minutes and discovering it on the invoice.

VoIP Security Controls

Technical measures that protect business VoIP systems from attack.

SIP Authentication Hardening

Strong, unique credentials for SIP accounts — default passwords changed and brute-force protection enabled.

Encrypted Call Transport

SRTP for media encryption and TLS for SIP signalling — prevents eavesdropping on call content.

Toll Fraud Detection

Alerts and automatic blocks when unusual call patterns are detected — international call limits enforced.

SBC and Firewall Controls

Session border controllers and firewall rules restrict VoIP traffic to authorised sources.

VoIP Security Checklist

Essential security controls for business VoIP systems.

Default SIP passwords changed

All SIP account credentials unique and strong — no manufacturer defaults in use.

SRTP and TLS enabled

Call content and signalling encrypted in transit on all VoIP connections.

International call limits configured

Spend and volume thresholds set — automatic block triggers active for anomalous usage.

Session border controller in place

VoIP system not directly internet-facing — SBC provides a security and NAT traversal layer.

Fraud detection monitoring active

Real-time alerts configured for unusual call patterns — not waiting for the monthly invoice.

Staff trained on vishing awareness

Team understands vishing tactics and the correct procedure for handling suspicious calls.

VoIP Security FAQs

Secure Your Business VoIP System

AMVIA reviews your VoIP security configuration, implements fraud protection and encrypted call transport, and monitors VoIP infrastructure as part of a managed service.