Protect distinct surfaces
A PBX has administration, signaling and media surfaces, plus dependencies such as backups and provisioning. A phone's permission to make a call should not grant access to the management interface. Separate network access and credentials by role.
Limit the cost of a compromised account
Give extensions only the calling permissions their users need. Restrict high-cost destinations where inappropriate, and arrange carrier usage notifications or limits where supported. A strong password alone does not make an unrestricted outbound route a sound design.
Keep administrative interfaces behind a restricted access path. Review vendor security guidance and maintenance status. Encryption addresses confidentiality and integrity on configured paths; it does not replace access policy, patching or destination controls.
Make recovery possible
Protect backups as sensitive data, store them away from the PBX and document who can restore them. Test restores in isolation to avoid duplicate registrations and chargeable calls. Keep an incident contact path outside the phone system itself.
For suspected compromise, preserve useful evidence, constrain affected access and work with the carrier on anomalous calling. Rebuild confidence in the system before restoring broad access. Do not disable security controls merely to make a diagnostic test pass.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.