In brief: Telecoms infrastructure is a high-value target for cybercriminals — attacks on VoIP systems, SIP trunks, and cloud communications platforms can cause immediate financial damage and long-term reputational harm. This guide covers the key cybersecurity considerations for SA telecoms resellers and their clients.
Why Telecoms Infrastructure Is a Target
Business communications infrastructure sits at the intersection of two high-value attack targets: financial systems (because calls can generate fraudulent charges) and corporate data (because conversations contain sensitive business information). For attackers, a compromised VoIP system offers both a direct monetisation path (toll fraud) and a potential surveillance mechanism (call interception).
The attack surface has grown significantly as telecoms infrastructure has moved from proprietary hardware to IP-based software. A 3CX or FreePBX server running on a standard Linux VM is fundamentally the same attack surface as any other web application — subject to the same vulnerabilities, exploits, and misconfigurations that affect all internet-facing software.
Radware, a leading cybersecurity vendor specialising in DDoS protection and application security, has documented the telecoms vertical as one of the highest-risk sectors for cyber attacks — both because of the financial value of the infrastructure and because telecoms providers often serve as carriers of other industries’ critical communications, making them attractive targets for disruption-motivated attackers.
The Threat Landscape for SA VoIP in 2025
Automated SIP scanning: Botnets continuously scan internet IP ranges for exposed SIP services (port 5060/5061). A PBX system exposed directly to the internet without protection will see thousands of authentication attempts daily. These scans are fully automated and operate 24/7 from IP addresses worldwide.
Toll fraud: The most financially damaging attack for SA businesses. Automated fraud tools can generate thousands of calls to premium international destinations within hours of gaining access to a SIP account. Financial damage ranges from R10,000 to R500,000+ before detection and remediation.
DDoS attacks: Distributed denial of service attacks against VoIP infrastructure can take contact centres and business phone systems offline. SIP flooding, registration storms, and INVITE floods are VoIP-specific DDoS techniques that traditional firewall rules may not filter effectively.
Data interception: Unencrypted SIP calls transmitted over public networks can theoretically be captured and decoded. This is most relevant for businesses handling sensitive conversations (legal advice, medical consultations, financial transactions) where call privacy is a legal requirement.
Ransomware targeting communications infrastructure: Ransomware attacks targeting business servers increasingly include VoIP servers. A 3CX server running on an unpatched Windows Server VM is as vulnerable to ransomware as any other Windows system. Loss of VoIP infrastructure in a ransomware attack can be more immediately damaging to operations than loss of file servers.
DDoS Protection for VoIP Infrastructure
DDoS protection for VoIP is a specialist requirement. Standard web application firewalls and volumetric DDoS protection don’t always handle VoIP-specific floods correctly. For organisations running self-hosted PBX infrastructure, several protection approaches are available:
Upstream carrier DDoS protection: Hosting the PBX at a data centre with upstream DDoS scrubbing (Hetzner, AWS, Azure, GCP all include baseline DDoS mitigation) provides volumetric attack protection without requiring dedicated appliances.
Session border controllers: SBCs (AudioCodes, Ribbon, Grandstream UCM SBC functions) provide protocol-layer protection against SIP floods and anomalous signalling. An SBC as the internet-facing edge of a PBX deployment is best practice for any deployment handling significant call volumes.
Cloud-hosted PBX: Migrating from self-hosted to a managed cloud PBX (3CX Cloud, Yeastar Cloud) transfers the DDoS protection responsibility to the vendor, who manages this at scale. For most SA SME deployments, cloud-hosted PBX with vendor-managed infrastructure provides better DDoS resilience than self-hosted at equivalent cost.
Practical Security for SA Resellers: Priority Actions
Never expose SIP services directly to the internet without protection. Use an SBC, firewall rules limiting SIP access to known IP ranges, or a VPN tunnel for SIP trunk connectivity where the provider supports it.
Patch promptly. Keep PBX software (3CX, Yeastar, FreePBX), operating systems (Linux/Windows), and phone firmware current. The 3CX supply chain attack of 2023 demonstrated that even trusted vendor software can be compromised — staying on current versions ensures you have the latest security fixes.
Enable encrypted transport. Use TLS for SIP signalling and SRTP for media where supported. For healthcare, legal, and financial clients, encrypted transport is a compliance requirement, not optional.
Implement SIP trunk IP restriction. Configure your SIP trunk provider to only accept calls from your PBX’s registered IP address. This prevents fraudsters who obtain SIP credentials from using them from other IP addresses.
Monitor for anomalies. Set up alerting for unusual call patterns: calls to unusual destinations, unusual hours, or unusually high concurrent call counts. Most SA SIP trunk providers offer configurable alerts; configure them as part of every deployment.
What This Means for SA Telecoms Resellers
Cybersecurity is no longer a specialist add-on for telecoms resellers — it’s a core competency required for responsible deployment and managed service delivery. Clients who experience a toll fraud attack or a VoIP service disruption expect their reseller to have a plan and to execute it competently.
Building cybersecurity practices into your standard deployment checklist, managed service offering, and client communication (regular security briefings, threat advisories when relevant) differentiates you from resellers who treat security as someone else’s responsibility. In 2025, “we take security seriously” needs to be backed by specific practices, not just assurances.