VoIP Security: How to Protect Your Business Calls from Attack
VoIP phone systems face specific security threats — including call interception, toll fraud, and phishing through voice calls (vishing). This guide explains the most significant VoIP security risks facing UK businesses and the practical controls that reduce them.
VoIP Security: Why It Matters
Toll fraud, call interception, and vishing are the primary VoIP security threats for UK businesses. Toll fraud alone can generate losses of thousands of pounds within hours of a system being compromised. AMVIA deploys SRTP/TLS encryption, SIP hardening, and real-time fraud detection as standard on all managed VoIP deployments.
Explore VoIP security optionsMost UK businesses moving off the old phone network treat the switch to VoIP as a telecoms decision. It is a security decision. A voice system reachable over the internet is a server reachable over the internet — and attackers scan for it around the clock. This page sits under our business VoIP pillar and explains the threats, the controls, and where managed cybersecurity cover the gaps a typical installer leaves open.
Why does VoIP security matter for UK businesses?
VoIP is attacked because it offers something most cyberattacks do not: direct, immediate financial payoff. The Communications Fraud Control Association estimates global telecommunications fraud costs the industry around $38–40 billion annually (CFCA survey, market estimate as of 2026), with toll fraud a significant share. The UK's migration off the old PSTN network, due to complete by 31 January 2027, is widening the attack surface as more firms expose voice systems to the public internet.
The risk is concentrated and fast. Unlike a slow data breach, a compromised phone system bleeds money in hours, usually overnight or across a weekend when no one is watching the call logs.
- Toll fraud turns your phone system into someone else's revenue stream
- SIP scanners probe internet-facing systems continuously, not occasionally
- Unencrypted calls can be captured on shared or poorly segmented networks
- Voice phishing targets your staff, not your switchboard
What are the main VoIP security threats?
The four threats that matter for UK SMEs are toll fraud, SIP scanning, call interception and vishing. Each has a clear technical control and, in the case of vishing, a human one. Treating them together — voice plus the wider security stack — is what separates a managed service from a phone install.
How does toll fraud work, and how do you stop it?
Toll fraud (international revenue share fraud) happens when attackers gain VoIP access through brute-force attacks, credential stuffing or default-password exploitation, then place large volumes of calls to premium-rate international destinations they profit from. "An undetected attack running for 48 hours over a weekend...can generate bills of tens of thousands of pounds." Single weekend attacks producing losses above £50,000 have been documented in UK cases (typical 2026 range).
Prevention requires layered controls:
- Strong, unique passwords on every SIP account
- Failed-authentication alerting with automatic lockout
- Blocking calls to high-risk international destinations by default
- Daily and weekly spend limits with automatic cut-offs
- Real-time monitoring for unusual call patterns, not month-end invoice review
What is SIP scanning, and how is it blocked?
SIP scanning is the automated probing of internet-facing IP addresses to find VoIP systems and test default credentials. Tools such as SIPVicious are freely available, so this is constant background noise on any exposed system. Protection means never exposing SIP ports directly to the public internet, enforcing strong non-default passwords of at least 16 characters, configuring fail2ban-equivalent brute-force protection, and restricting SIP registration to known IP ranges.
Can business calls be intercepted or overheard?
Yes. Unencrypted VoIP calls can be captured on shared network segments — a real risk for businesses using shared or public Wi-Fi, poorly segmented guest networks, or already-compromised internal networks. The fix is to enable SRTP, which encrypts the voice content, and TLS, which encrypts the SIP signalling, on every business VoIP system. Treat an unencrypted call the same way you would treat a plain-text password.
How does vishing target your staff?
Vishing — voice phishing — uses phone calls to manipulate staff into disclosing credentials, authorising payments or granting system access, with attackers impersonating HMRC, banks, IT support, couriers or senior management. STIR/SHAKEN caller authentication and call filtering block many spoofed numbers, but the decisive control is human. As the NCSC's phishing guidance makes clear, staff awareness is a primary defence: legitimate IT, banks and HMRC never request passwords on unsolicited calls. Our anti-phishing and managed cybersecurity services cover this training alongside the technical filtering.
What does a session border controller do for VoIP security?
A session border controller (SBC) is a network device that sits at the boundary between your internal VoIP network and the public internet. It hides internal VoIP topology from external probing, enforces access control on SIP traffic, defends against SIP-based denial-of-service attacks, handles NAT traversal, and enforces encryption policy.
For any deployment involving SIP trunking or Direct Routing to platforms such as Microsoft Teams, an SBC should be treated as essential infrastructure rather than optional. If you are connecting a hosted phone system to the wider internet, the SBC is the front door — and it should be locked.
Denial-of-service attacks against VoIP infrastructure overwhelm SIP services or your internet connection with malicious traffic, potentially taking the phone system fully offline. SBC-level rate limiting, firewall rules restricting SIP to known sources, bandwidth management and disaster-recovery call routing to mobiles or alternative sites keep calls flowing under attack.
In-house DIY versus AMVIA managed VoIP security
A phone installer configures call routing. A security partner configures defences. The difference shows up the first time someone scans your system at 2am on a Saturday.
| VoIP security control | Typical DIY / installer setup | AMVIA managed VoIP security |
|---|---|---|
| SIP authentication | Default or weak passwords | Strong unique credentials, brute-force lockout |
| Call encryption | Often left off | SRTP + TLS enforced on every endpoint |
| Toll-fraud detection | Spotted on the next invoice | Real-time alerts and automatic blocks |
| Internet exposure | SIP port open to the world | SBC and firewall restrict to known sources |
| Vishing defence | None | Staff awareness training + call filtering |
| Monitoring | None | Continuous, tied to the wider security stack |
What are the VoIP security best practices for UK SMEs?
The baseline below closes the gaps attackers exploit most. None of it is exotic; the failure is almost always that no one owns it. That ownership is the point of a managed service.
- Change all default SIP passwords immediately — at least 16 characters mixing letters, numbers and symbols
- Enable SRTP and TLS on your VoIP platform — unencrypted voice is plain-text risk
- Deploy a session border controller — never expose a PBX/VoIP SIP interface directly to the internet
- Set international call limits and spend caps with alerts and automatic blocks
- Implement real-time fraud monitoring rather than waiting for the monthly bill
- Segment your voice network onto a separate VLAN from general data traffic
- Train finance, reception and PA staff on vishing at regular intervals
- Patch VoIP firmware and software with the same discipline as servers and workstations
Ofcom's guidance on the PSTN switch-off is a useful reference point for planning the move, but the switch is the moment to get these controls in place — not after the first fraudulent bill.
How does AMVIA secure business VoIP?
AMVIA delivers VoIP security as part of one accountable managed service, not a bolt-on. We harden SIP authentication, enforce encrypted call transport, deploy and manage the SBC, and run continuous toll-fraud detection — then connect it all to the same security operations that protect your Microsoft 365 and endpoints. One provider, security-first, Microsoft-certified engineers.
That single-provider model matters: when voice, network and identity are watched together, an unusual call pattern is read in context rather than in isolation. For most SMEs that is the difference between catching fraud in minutes and discovering it on the invoice.
VoIP Security Controls
Technical measures that protect business VoIP systems from attack.
SIP Authentication Hardening
Strong, unique credentials for SIP accounts — default passwords changed and brute-force protection enabled.
Encrypted Call Transport
SRTP for media encryption and TLS for SIP signalling — prevents eavesdropping on call content.
Toll Fraud Detection
Alerts and automatic blocks when unusual call patterns are detected — international call limits enforced.
SBC and Firewall Controls
Session border controllers and firewall rules restrict VoIP traffic to authorised sources.
VoIP Security Checklist
Essential security controls for business VoIP systems.
Default SIP passwords changed
All SIP account credentials unique and strong — no manufacturer defaults in use.
SRTP and TLS enabled
Call content and signalling encrypted in transit on all VoIP connections.
International call limits configured
Spend and volume thresholds set — automatic block triggers active for anomalous usage.
Session border controller in place
VoIP system not directly internet-facing — SBC provides a security and NAT traversal layer.
Fraud detection monitoring active
Real-time alerts configured for unusual call patterns — not waiting for the monthly invoice.
Staff trained on vishing awareness
Team understands vishing tactics and the correct procedure for handling suspicious calls.
VoIP Security FAQs
Yes — the classic attack is toll fraud: criminals compromise a system or account and pump premium-rate calls through it, with losses that can reach tens of thousands (industry cases run to £50,000+) before anyone reads the bill. SIP attacks and call interception are rarer but real.
Attackers use your phone system to route expensive calls they profit from. Prevention is unglamorous and effective: strong credentials and MFA on the platform, international and premium-rate calling restricted by policy, rate limits, and monitoring that flags abnormal call patterns fast.
On a properly configured business platform, yes — signalling and media encrypted in transit (TLS/SRTP). The qualifier matters: defaults vary by provider, which is why VoIP security is a configuration discipline, not a product feature you can assume.
Both, with a boundary: the provider secures the platform; you (or your managed provider) secure the accounts, devices and calling policies. When AMVIA runs the phones, the connectivity and the security together, that boundary stops being a gap.
Secure Your Business VoIP System
AMVIA reviews your VoIP security configuration, implements fraud protection and encrypted call transport, and monitors VoIP infrastructure as part of a managed service.
Related Resources
What Is Business VoIP?
How business VoIP works and how it differs from the PSTN it is replacing.
The Complete Cybersecurity Guide
How VoIP security fits into a broader layered security strategy for UK businesses.
Anti-Phishing for UK Businesses
How to protect against phishing and vishing attacks targeting your team.
Business VoIP Solutions
AMVIA's managed VoIP services with security controls included as standard.