PBX Security
PBX (or PABX), Private Branch eXchange systems can be found in virtually all medium and large sized organisations. A PBX works as a small telephone switch handling internal phone calls without involving a telephone company. Modern PBX systems have a wide range of features which allow owners to increase communication efficiency while reducing costs.
Risks
Risks stem from the fact that modern PBXs are laden with features which, if configured incorrectly can be left open to abuse. Service theft can result directly in monetary loss. Improperly configured PBX systems may allow malicious persons to make phone calls at the expense of the of PBX owner.
Advantages
By employing specialist PBX security services you can guard against service theft resulting from PBX subversion and increase availability of your telecoms infrastructure.
PBX security services focus on key attack vectors such as management interfaces, DISA (Dial In System Access) and attacks originating from inside such as call forwarding. Types of issues commonly discovered are unauthorized access to PBX management interface and call forwarding to international and premium rate numbers.
These services are offered by a combination of means tailored to the engagement. This may include interviews with relevant personnel, PBX configuration review and enumeration of undocumented features
After mapping risks and associated business impact steps to mitigate risks can be taken. |