Telappliant
Cyber Security Guide · 15 August 2026

Is your desk phone putting your business at risk?

Handsets and phone systems are network devices. The default settings, firmware gaps and toll fraud risks worth checking this month.

By the Telappliant team

A VoIP desk phone connected by ethernet on an office desk

A desk phone is a small computer with a microphone, a network port and, very often, a default administrator password and firmware from three years ago. Phone systems rarely appear on the patching schedule, which is precisely why they are worth an hour of attention.

What actually goes wrong

  • Toll fraud: compromised extensions used to dial premium or international destinations overnight and at weekends
  • Default web interfaces reachable from the internet with factory credentials
  • Unencrypted signalling and media, allowing call interception on a flat network
  • Old firmware with published vulnerabilities on handsets and gateways
  • A PBX left exposed after a migration that nobody decommissioned

Toll fraud is the expensive one

Attackers register to a weakly protected extension and generate traffic to revenue-share destinations. Losses build in hours, usually starting on a Friday night. Controls are simple: strong unique SIP credentials, international dialling barred by default and enabled per user, concurrent call and spend limits, and alerting on unusual destinations or volumes.

Harden the estate

  • Change every default administrator password on handsets and the phone system
  • Disable the handset web interface, or restrict it to a management network
  • Put voice on its own VLAN, separated from data and guest traffic
  • Enable TLS for signalling and SRTP for media where the platform supports it
  • Keep handset and gateway firmware current, and retire models the vendor no longer patches
  • Never expose SIP or a PBX management interface directly to the internet

Cloud platforms shift, but do not remove, the risk

With a hosted platform the provider patches the core, which removes most of the appliance risk. Your responsibility becomes account security: MFA on the administration portal, sensible dialling permissions, spend alerts and prompt removal of leavers' extensions.

Do not forget the analogue leftovers

Lift lines, alarm diallers and door entry often sit on the same estate and are being forced onto IP by the PSTN switch-off. Plan and test them alongside the phones rather than discovering them at cutover.

A short checklist

  • Inventory every handset, gateway and PBX with firmware versions
  • Reset default credentials and restrict management access
  • Bar international dialling by default and set spend alerts
  • Segment voice traffic and enable encryption
  • Add phone system firmware to the normal patch cycle

Next steps

Frequently asked questions

Was this article helpful?

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a technology partner

Get direct access to the people who manage, support and improve your technology. Our teams work together across our locations, so whether the issue is IT, communications, connectivity or security, we can bring in the right expertise without passing you between separate providers.

  • One integrated support team
  • Expertise across IT, communications, connectivity and security
  • Connected support across our locations
Technology team reviewing plans together before a consultation
Call us Book consultation