Summary
Protecting your organisation’s telephony systems from cyber attacks and telecoms All PBX systems should follow the NICC’s Requirements on Communications Providers in relation to Customer Line Identification display services and other related services A Private Branch Exchange (PBX) is a telecommunications system used to manage and route incoming and outgoing telephone calls within an organisation. Implementing the steps outlined in this guidance will reduce the likelihood of attackers compromising your PBX system, whether to commit fraud, instigate denial of service (DoS) attacks, or exploit telecoms channels. This guidance is aimed at administrators and/or procurers of PBX systems, so some knowledge of telecommunications is assumed. As with any system that’s connected to the internet, PBX systems, if not configured correctly, are at risk of being compromised by attackers. Attackers can find vulnerabilities by using scanners or by exploiting system weaknesses such as unchanged default passwords, open SIP ports, or incorrectly managed Once inside, criminals can route high-rate international or premium-rate numbers through the system. These attacks (also known as ‘dial-through fraud’) are generally prolonged and involve expensive telephone numbers being dialled hundreds or even thousands of times.