Your SIP Credentials Are a Bank Card: Hardening a Business Phone System
SIP credentials authorise calls, and calls cost money. That makes a stolen extension password more like a lost bank card than a leaked document: the damage is measured in a bill, it accumulates fast, and it happens while nobody is looking — overnight, and disproportionately at weekends and on public holidays.
This is the practical hardening list, in the order it is worth doing.
1. Fix the passwords
Most compromises are not clever. They are an extension whose password is the extension number, or the handset default that was never changed. Automated scanners find these within hours of a device appearing on the internet.
Extension passwords should be long, random and different from each other. Nobody types them — the handset provisions them — so there is no argument for them being memorable.
2. Put a ceiling on what an extension can dial
The single most effective control, because it caps the damage rather than trying to prevent every intrusion. Most extensions have no business dialling international premium destinations at three in the morning.
- Restrict international dialling to the extensions that genuinely need it.
- Bar destination ranges you never call.
- Set a spend or duration ceiling per extension per day.
A compromised extension that can only call locally is an annoyance. One with unrestricted international access is a five-figure weekend.
3. Watch for the pattern, not the intrusion
Fraud has a shape: a burst of calls to the same unusual destination, outside business hours, from an extension that normally makes ten local calls a day. That pattern is detectable long before the bill arrives, and alerting on it is more useful than any amount of perimeter hardening. The toll fraud guide covers the detection side in detail.
4. Do not expose what does not need exposing
A phone system's administration interface does not need to be reachable from the public internet. Neither does a handset's web interface. Where remote access is genuinely required, it belongs behind a controlled path rather than an open port — the argument for privileged access control set out in the privileged access piece.
5. Treat provisioning files as credentials
A provisioning file contains the extension's password. If it can be fetched from a guessable address without authentication, the password is effectively public. Ask how your provider secures provisioning; it is a question that separates providers quickly.
6. Remove people the day they leave
Extensions belonging to former staff are a standing risk, particularly where somebody left on bad terms and knows the softphone credentials. Disabling an extension takes seconds and is worth putting into the leaver process next to the door key.
What to do if it has already happened
Speed matters more than diagnosis. Disable the affected extension, bar the destination range, change credentials across the account rather than only the one you found, and call your provider — a carrier that runs its own network can stop traffic at the network rather than waiting for someone else to act. Then work out how it got in.
Frequently Asked Questions
How do attackers find a phone system?
Automated scanning. Nothing about the business is targeted — systems reachable from the internet are found and tested against common passwords within hours.
What is the single most effective control?
Dialling restrictions. They cap the loss even when everything else has failed, which no other control does.
Why do attacks happen at weekends?
Because nobody is watching. Fraud placed on a Friday night can run until Monday morning if nothing alerts.
Are cloud phone systems safer than on-premise ones?
The exposure is different rather than automatically lower. What changes is who is responsible for patching and monitoring the core, and whether anyone is watching your traffic pattern at all.
Getting started
Do the dialling restrictions first — it is an afternoon and it caps the worst case. Then audit extension passwords and remove leavers. The WOCOM team can review the restrictions on your account with you.
Continue exploring
Ready to upgrade your communications?
Talk to our team about the right solution for your business.
Book a Demo Contact SalesEverett Kildare is WOCOM's voice and infrastructure specialist, with more than 25 years of experience designing and running carrier-grade voice, SIP and virtualization infrastructure. Holding a BSc in Information Technology, he has built, secured and migrated phone systems for businesses of every size. Everett writes WOCOM's technical coverage of SIP trunking, cloud PBX, contact centres, business continuity and migration.