Why Your Business Phone System is a Security Risk.
Guest author: Anthony Luca, APJ Cisco Collaboration SpecialistWe all know that cyber security is becoming more problematic, every year we hear of another high profile attack on a large organisation, Medibank and Optus are just two recent attacks.
What we don’t hear about is that 43% of cyber attacks target SMBs (https://cyberwardens.com.au/wp-content/uploads/2024/03/Research-Report-Building-a-culture-of-cyber-safety-in-Australian-small-businesses.pdf) with the average cost of cybercrime to each business being $46k (https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/small-business-cyber-security).
With the shift to cloud based business services (think email, CRM and accounting systems), we get the benefit of always up-to-date, accessible from anywhere access to critical business systems. But we also get the benefit of outsourcing the security risk of those systems to the company who builds and runs those systems, no longer having to hold the risk ourselves.
One service that has been slow to move to the cloud is the traditional phone system. Today more than ever, it poses an additional security risk to your business. The three main risks are:
- Risk of toll-fraud. This is where an attacker compromises your phone system to generate very expensive international calls. Check your contract, because you as the small business owner are liable for these charges (https://smb.optus.com.au/opfiles/Business/PDFs/PBX_Fraud_Awareness_Guide.pdf). There are a number of ways in which a phone system can be compromised, including through the voicemail number, through a phone that doesn’t have any protection, or through the Phone System itself. Once an attacker has the right access, they can then initiate a number of international calls to expensive destinations, and you will be liable for those charges. Charges of $10,000+ are not uncommon!
- Risk of compromise. Attackers look for any weak system in your network to initiate their attack. Modern phone systems are connected to the internet for connectivity and for remote access for management purposes. If your Phone System isn’t secured adequately, it could be the system that allows attackers to access your entire network! To ensure the Phone System isn’t compromised, it needs to be protected using well a configured firewall, as well as strong passwords, and two-factor authentication. It also needs to be patched frequently, especially with any security patches. So is your phone system being patched frequently? Is your Phone System vendor keeping up to date with security patches?
- Secure Credit Card Payments. Does your business take credit card payments over the phone? If so, you are likely not PCI-DSS compliant. PCI-DSS stands for Payment Card Industry Data Security Standard and applies to any entity that stores, processes and/or transmits cardholder data, including those businesses that take payment over the phone. The standard is quite onerous, so having a Phone System that ensures you can still process credit card payment, but not capturing any cardholder data allows you to meet your PCI-DSS requirements whilst still taking payments over the phone!
- Unfortunately, the responsibility is on you, the SMB owner. Has your Phone System supplier setup your network and Phone System using best practices (https://www.ncsc.gov.uk/pdfs/guidance/private-branch-exchange-best-practice.pdf)? Have you had a 3rd party security expert verify your phone systems security? These are not easy questions to answer for any business, let alone for a small business.
Unfortunately, the responsibility is on you, the SMB owner. Has your Phone System supplier setup your network and Phone System using best practices (https://www.ncsc.gov.uk/pdfs/guidance/private-branch-exchange-best-practice.pdf)? Have you had a 3rd party security expert verify your phone systems security? These are not easy questions to answer for any business, let alone for a small business.
When choosing a Cloud based phone system, you need to answer two questions
- Does my Cloud based Phone System deliver the features I need?
- Can I trust the Phone System Vendor to secure their Phone System effectively?
Here at Cisco, we are one of the largest security suppliers in the industry, and all of our products, including our Webex Cloud Phone System, has security built in from the ground up. Talk to your Nexgen representative to learn more about how our Webex Platform not only can give you a better Phone System experience, but a much more secure one too.
Ready to revolutionize your communication and save up to 70% on your calls?
Upgrade to the latest small business phone system technology today and get started with a free quote below!