Is Your Business Phone System Safe? 7 Security Mistakes Owners Make (and How to Fix Them)

Small-business owner reviewing a secure cloud phone system in a modern office

A business phone system is no longer just a desk phone and a cable in the wall.

Today, a cloud PBX or hosted PBX may manage your main number, call forwarding, voicemail, recordings, staff mobiles, desktop apps, messaging and customer call flows. That flexibility is useful, but it also means your phone system needs the same care as your email, accounting software and other online services.

Recent breaches involving well-known communications providers have reminded businesses that phone systems can be targeted too. Attackers may be looking for customer information, admin access, voicemail messages or the ability to make expensive calls through your account.

The good news is that many risks come from simple, fixable mistakes. Here are seven of the most common ones.

1. Using weak or shared admin logins

One of the biggest risks is also one of the easiest to overlook: several people using the same administrator username and password.

Shared logins create two problems. First, if the password is stolen, an attacker may gain control of important settings. Second, you cannot easily tell who changed a call route, added a user or changed a voicemail setting.

A weak password makes the problem worse, especially if it is reused for email, Microsoft 365, Google Workspace or another business service.

The fix

  • Give every administrator their own login.
  • Use a long, unique password or passphrase.
  • Turn on multi-factor authentication (MFA) wherever your provider supports it.
  • Do not share admin credentials by email, text message or chat.
  • Keep everyday user accounts separate from administrator accounts.
  • Remove administrator access when someone no longer needs it.

MFA adds another check at login, such as an authentication app or security key. It helps protect your account even if someone obtains a password.

The Australian Cyber Security Centre recommends MFA for cloud services and important business accounts. Your phone system should be treated as one of those important services.

2. Forgetting call forwarding and voicemail rules

Call forwarding is useful when staff work from home, travel or share after-hours duties. But an old forwarding rule can quietly send business calls to the wrong person, or to a number controlled by someone who should no longer have access.

Voicemail settings deserve the same attention. An attacker who gains access to a voicemail box may be able to listen to messages, change greetings, forward calls or use information from messages to impersonate your business.

Common examples include:

  • Calls still forwarding to a former employee’s mobile
  • After-hours calls going to an old contractor
  • Voicemail PINs that are simple or unchanged
  • A temporary holiday rule left active for months
  • A user allowed to change forwarding without approval

The fix

Review every forwarding and voicemail rule at least quarterly. Also review them whenever someone changes role or leaves the business.

Check:

  • Where the main number rings during business hours
  • Where calls go when nobody answers
  • After-hours and holiday routes
  • External forwarding numbers
  • Voicemail greetings and PINs
  • Who is allowed to change call flows

Keep forwarding rules as simple as possible. If a rule is no longer needed, remove it rather than leaving it available “just in case”.

Small-business manager reviewing cloud phone users and permissions

3. Leaving former staff and unmanaged devices signed in

A cloud phone system can work across desk phones, laptops, browsers, smartphones and tablets. That is convenient for your team, but it creates more places where an account may remain signed in.

When an employee leaves, their desktop app may still be active. Their mobile phone may still have access to the business number. A browser session may still be open on a home computer.

You may also have old devices that nobody is actively managing. If a phone or laptop is lost, stolen or sold without being signed out, the next person may be able to access the account.

The fix

Add phone-system access to your staff offboarding process.

When someone leaves or changes role:

  1. Disable their user account.
  2. Sign out or revoke all active sessions.
  3. Remove their mobile and desktop devices.
  4. Delete or reassign their phone number and extension.
  5. Remove forwarding rules linked to them.
  6. Change shared voicemail or team access where necessary.
  7. Check whether they had administrator rights.

Keep a current list of approved devices and users. If your provider offers remote sign-out, device management or the ability to wipe app data, make sure your team knows how to use it.

4. Giving users more access than they need

Not every employee needs permission to change call routing, export reports, manage recordings or create new users.

Giving everyone full access may seem easier during setup, but it increases the impact of a stolen login or accidental change. A user who only needs to answer calls should not automatically be able to change the company’s main number.

This is known as giving people the least access they need. You do not need to use the technical term to apply the idea.

The fix

Create simple roles based on responsibilities.

For example:

  • Standard user: make and receive calls, manage their own voicemail
  • Team leader: manage a small team’s call settings
  • Phone system administrator: manage users, routes and system settings
  • Billing user: view invoices without changing call settings

Review these roles every few months. Ask whether each person still needs their current access, not just whether they can be trusted.

Keep the number of administrators small. If your phone provider or IT company manages the system, make sure their access is named, limited and removed when the work is complete.

5. Assuming staff will always recognise a phone scam

A phone system can be technically well configured and still be compromised through people.

Someone may call pretending to be your phone provider, an IT technician or a senior manager. They may claim there is an urgent fault and ask for a password, MFA code or remote access.

This is called social engineering. It works because the request sounds plausible and urgent.

Staff may also receive fake login links by email or text. A convincing sign-in page can capture their phone-system password before they realise anything is wrong.

The fix

Give staff a simple rule:

No legitimate provider or manager should ask for your password or MFA code over the phone.

Train staff to:

  • End unexpected support calls and call the provider back using a known number.
  • Never approve an MFA request they did not initiate.
  • Avoid signing in through links in unexpected messages.
  • Report suspicious calls or login prompts without fear of blame.
  • Confirm unusual requests through a second channel.

Your provider may have a support process that uses account verification. Make sure staff know what that process looks like so they can distinguish it from an attacker asking for access.

6. Having no alerts for account or system changes

If someone adds a new administrator, changes the main call route or signs in from an unusual location, would you know?

Many businesses only discover a problem after customers report that calls are going somewhere strange, or after they receive an unexpectedly large phone bill.

Alerts can turn a silent change into an early warning. They may notify you about a new login, password reset, user creation, forwarding change or unusual calling activity.

The fix

Ask your provider which alerts are available and turn on the useful ones.

Prioritise notifications for:

  • New administrator accounts
  • Password and MFA changes
  • New devices or sessions
  • Call-forwarding changes
  • Changes to the main number or auto-attendant
  • Unusual international or premium-rate calls
  • Sudden increases in call volume
  • Failed login attempts

Send alerts to at least two trusted people, not just one employee’s inbox. Review call activity and invoices regularly as well. A sudden rise in overseas calls can be a sign of account misuse or toll fraud.

7. Not reviewing access after staff leave

Disabling a former employee’s email account does not necessarily remove their phone-system access.

They may still appear as an active user, retain an extension, have access to recordings or remain listed as a forwarding destination. Contractors, temporary staff and former IT providers can be missed too.

This is often an administrative problem rather than a technical one. Nobody owns the review, so it does not happen.

The fix

Schedule an access review at least every three months, and whenever someone leaves.

Compare your phone-system user list with your current staff list. Check:

  • Active users and extensions
  • Administrators
  • External support accounts
  • Mobile and desktop devices
  • Call recording access
  • Shared voicemail boxes
  • Forwarding destinations
  • Integrations and connected apps

Keep a short record of when the review was completed and who approved the changes. This makes it easier to spot gaps next time.

A practical cloud PBX security checklist

Use this quick checklist with your team or phone provider:

  • Does every administrator have an individual login?
  • Is MFA enabled for the phone-system admin portal?
  • Are admin passwords unique and protected?
  • Have all forwarding and voicemail rules been reviewed?
  • Are former staff and old devices removed?
  • Do users have only the access they need?
  • Do staff know how to respond to suspicious support calls?
  • Are alerts enabled for account and call-setting changes?
  • Are unusual call volumes and phone bills reviewed?
  • Is there a scheduled access review?

Small-business owner completing a cloud phone security checklist

A secure hosted PBX does not require you to become a cyber-security expert. Start by knowing who can access the system, what they can change and where your calls can be sent.

Then add MFA, review access regularly, train your staff and turn on useful alerts. These straightforward steps will reduce the chance of an old setting, stolen login or former device becoming a serious business problem.

For more practical advice on getting value from your business phone system, see our guide to common small-business VoIP mistakes. You can also review the Cloud Phone Company features and ask your provider which security controls are included in your plan.