
That shift brings real risks. Eavesdropping on sensitive calls. Caller-ID spoofing. Toll fraud that racks up thousands in unauthorized charges overnight. Denial-of-service attacks that flood your system and block legitimate calls. Misconfigured PBX settings that leave the front door wide open.
This guide breaks down what secure SIP trunking actually means, how TLS and SRTP protect your calls, the threats you need to guard against, compliance considerations, and what to ask before signing with a provider.
Key Takeaways
- TLS protects signaling; SRTP protects audio — you need both, not just one
- Encryption isn't a complete security program: SBCs, access controls, and monitoring matter just as much
- STIR/SHAKEN authenticates caller identity but doesn't encrypt anything on its own
- Confirm a provider's failover, monitoring, and compliance documentation before you sign
What Is Secure SIP Trunking and How Does It Work?
Secure SIP trunking is a SIP trunk connection protected end to end with encrypted signaling, encrypted media, and authenticated network borders. It links your business phone system (PBX or UC platform) to the public telephone network over the internet instead of copper lines, while keeping call control and audio from traveling in the clear.
Session Initiation Protocol (SIP) handles signaling—setting up, managing, and tearing down each call. People often treat "VoIP" and "SIP trunking" as the same thing, but they aren't. VoIP is the broad category of carrying voice over IP. SIP is one signaling protocol inside that category, and SIP trunking is the service that connects your phone system to the outside telephone network.
Two Layers You Need to Protect
Every SIP call involves two distinct communication layers:
- SIP signaling — carries call setup, routing, registration, caller ID, and session details
- RTP (Real-time Transport Protocol) — carries the actual audio once the call connects
Each layer needs its own protection, which is why secure trunks pair TLS with SRTP.
TLS and SRTP, Explained Simply
TLS (Transport Layer Security) encrypts and authenticates SIP signaling. It stops attackers from reading or tampering with call-control messages as they travel between your PBX and the provider's network.
SRTP (Secure Real-time Transport Protocol) encrypts and protects the integrity of the audio stream itself. According to RFC 3711, which defines the protocol, SRTP provides confidentiality, message authentication, and replay protection for RTP and RTCP traffic.
Here's the part that trips people up: TLS without SRTP still leaves your audio exposed. Anyone who captures the RTP stream can potentially reconstruct the conversation. Meanwhile, SRTP without protected signaling can leave caller IDs, phone numbers, and routing metadata visible, even if nobody can hear the call itself.
Both layers need evaluation together, not separately. A provider that offers TLS but treats SRTP as an afterthought hasn't given you a secure trunk.
The Role of SBCs and Certificate Authentication
A Session Border Controller (SBC) sits at the edge of your network and manages trusted connections. It:
- Hides your internal network topology from outside attackers
- Enforces security policies on incoming and outgoing SIP traffic
- Handles interoperability between different PBX and carrier systems
- Blocks unauthorized SIP traffic before it reaches your PBX
Certificates and endpoint authentication work alongside the SBC to confirm that both sides of a connection are who they claim to be, closing off a common entry point for attackers.
Put together—TLS for signaling, SRTP for media, and an SBC with certificate-based authentication at the border—you have secure SIP trunking rather than a plain internet voice path.

What Threats Does Secure SIP Trunking Help Prevent?
Each of these attacks hits a different layer of your phone system—and most succeed when one weak control is treated as enough.
Toll Fraud and International Revenue-Share Fraud
Toll fraud remains one of the costliest risks in business telephony. The Communications Fraud Control Association's 2023 survey found that global telecom fraud losses hit an estimated $38.95 billion, a 12% jump from the prior survey and roughly 2.5% of total industry revenue. PBX-related fraud ranked among the top reported methods.
Attackers typically exploit:
- Compromised extensions with weak or reused passwords
- Exposed PBX management interfaces reachable from the public internet
- Permissive international or premium-rate dialing rules
Once inside, they route calls to expensive international or premium-rate destinations and vanish before anyone notices—often leaving a multi-thousand-dollar bill.
Eavesdropping and Signaling Interception
Unencrypted signaling lets anyone monitoring traffic see:
- Caller IDs and phone numbers
- Routing paths and registration details
Unencrypted RTP goes further and exposes the actual conversation. For a law firm discussing case strategy or a medical office confirming patient details, that is not a theoretical risk.
Registration Hijacking, Spoofing, and Caller-ID Abuse
Attackers impersonate a trusted endpoint, then:
- Hijack registration and redirect incoming calls
- Place unauthorized outbound calls
- Manipulate caller-ID to appear legitimate
STIR/SHAKEN was designed to reduce this kind of abuse, though it is not a complete fix on its own.
Denial-of-Service and Call Flooding
Radware describes SIP INVITE flooding as an attack where a flood of call-setup requests overwhelms a SIP server or SBC's CPU, memory, and connection tables. The result: delayed call setup, dropped calls, or a system that simply can't take legitimate calls anymore.
Configuration Failures Are the Silent Killer
Most breaches don't start with a sophisticated exploit. They start with:
- Default administrator credentials never changed
- Unrestricted international dialing left switched on
- Open management interfaces reachable from anywhere
- Unpatched PBX software running known vulnerabilities
- Accidental fallback to unencrypted SIP when TLS negotiation fails
Password attacks, port scanning, ghost calls, and phishing aimed at PBX admins target people and configuration—not the carrier link. A secure trunk alone is not enough.

Security Controls, Compliance, and Reliability Considerations
Secure SIP trunking works best as a layered stack, not a single feature you turn on.
The Essential Security Stack
Encryption and edge protection
- TLS for signaling encryption
- SRTP for media encryption
- SBC protection at the network edge
Access control and operations
- IP allowlisting or authenticated access
- Strong, unique credentials
- Network segmentation
- Regular patching
- Call monitoring and fraud alerts
- Documented incident-response procedures
STIR/SHAKEN vs. Encryption
These two get confused often, so let's separate them clearly. STIR/SHAKEN authenticates caller identity and helps reduce spoofing. It does not encrypt signaling or media in any way.
The FCC's call authentication rules require most voice service providers to implement STIR/SHAKEN on IP portions of their networks. All providers, regardless of implementation status, must also file in the Robocall Mitigation Database.
Public Telephone Company maintains its own RMD filing and has completed STIR/SHAKEN implementation as part of its compliance obligations. Treat STIR/SHAKEN as complementary to TLS and SRTP—never a substitute for either.
Reliability Is More Than Encryption
A perfectly encrypted trunk that goes down during business hours doesn't help anyone. Reliability depends on:
- Redundant provider infrastructure and diverse network routes
- Sufficient bandwidth and quality internet service
- Quality of Service (QoS) configuration for voice traffic
- Power resilience and failover options
- Active network monitoring
- Clear service-level commitments from your provider
Industry Needs Differ
| Business Type | Priority Focus |
|---|---|
| Law firms | Call recording integrity, confidentiality |
| Medical/dental practices | HIPAA-aligned safeguards, patient data protection |
| Municipalities | Compliance documentation, audit trails |
| Multi-location businesses | Consistent security across all sites |
| Existing PBX owners | Compatibility and secure interconnection |
Compliance Isn't Automatic
SIP encryption alone does not make a business HIPAA or PCI DSS compliant.
HIPAA's Security Rule applies to any telephone system carrying electronic protected health information. It requires a documented risk analysis covering interception risk, access controls, and encryption capability—not just an encrypted trunk.
PCI DSS guidance for telephone payments focuses on the entire environment: call recording, storage, and agent access, not just the connection type.
Before selecting a provider, ask for:
- Encryption specifications in writing
- Authentication practices documentation
- Incident-response process details
- Fraud-control measures
- Current compliance filings (RMD status, FCC registrations)
- Support coverage details
How to Implement and Maintain Secure SIP Trunking
Secure SIP trunking takes planned configuration, a controlled cutover, and regular upkeep.
Start With an Inventory
Document your current environment before making changes:
- PBX or UC platform in use
- SBC (if you have one)
- Handsets and firmware versions
- Firewall rules and public IP addresses
- Codecs, extensions, and call destinations
- Remote users and their access needs
Configure Signaling and Media Security
- Verify TLS support on both your PBX and provider side, including which versions and certificate chains are accepted
- Enable SRTP for media and confirm whether it's optional or enforced; block insecure fallback when your call flows allow it
- Check firewall and NAT rules to allow secure traffic without exposing management interfaces unnecessarily
Harden Access and Calling Permissions
- Use unique administrator credentials for every account
- Apply least-privilege roles so users only access what they need
- Restrict access by IP or trusted authentication method
- Set geographic dialing controls to block unnecessary international calling
- Require strong voicemail PINs
- Keep management access separate from public SIP traffic
Place an SBC at the Network Edge
Place the SBC between your PBX and the public SIP trunk. It provides topology hiding, rate limiting, protocol normalization, and traffic filtering, plus the logging you'll need if something goes wrong later.

Test Before Going Live
Before cutting over production traffic:
- Place inbound and outbound test calls; verify registration, caller ID, two-way audio, DTMF, and transfers
- Confirm TLS on signaling and SRTP on media using provider logs or PBX diagnostics
- Test certificate validation, expiration alerts, and failover behavior when a route drops
Keep It Maintained
Build ongoing maintenance around these checks:
- Certificate renewal before expiration
- PBX and SBC software updates
- Periodic configuration reviews
- Call-pattern and spending threshold monitoring
- Scheduled security testing
Common troubleshooting issues:
- Failed calls after enabling TLS often trace back to certificate trust errors
- One-way audio usually points to NAT or firewall misconfiguration
- Unexpected fallback to insecure transport signals a negotiation mismatch worth investigating immediately
Document your final configuration, approved call destinations, and escalation contacts so your team can recover quickly if something breaks.
How to Choose a Secure SIP Trunking Provider
Not every provider labeling itself "secure" backs that claim with real controls. Use this checklist before signing anything.
Provider Evaluation Checklist
- Encryption: Are TLS and SRTP supported, enabled by default, and enforceable without insecure fallback?
- Authentication: How are certificates and endpoint credentials issued, rotated, and revoked?
- Fraud management: What monitoring, alerting, and traffic controls stop toll fraud?
- Redundancy: What failover, monitoring, and emergency calling support exist?
- Compatibility: Which PBX and SBC platforms does the provider support, and do they help with migration and testing?
- Documentation: Can they produce compliance filings, STIR/SHAKEN status, and an abuse-reporting process?
Questions to Ask Before You Sign
- Does your service encrypt both signaling and media, and which protocol versions do you support?
- Can insecure fallback be disabled or at least detected?
- How do you identify and stop toll fraud?
- How are certificates and credentials managed on your end?
- What happens if the primary connection or provider system fails?
- What support is available during an outage or suspected security incident?
If a provider can't answer these clearly, keep looking.
Whatever provider you evaluate, confirm the specific TLS, SRTP, SBC, and failover capabilities for your deployment rather than accepting generic VoIP marketing claims. Public Telephone Company has offered SIP trunking, hosted PBX, and unified communications since 1999, with cloud systems that scale from small offices to 100,000+ users.

Prioritize providers that can show:
- Encryption on by default, with insecure fallback disabled or detectable
- Clear certificate handling plus active toll-fraud monitoring
- Documented failover, monitoring, and emergency calling support
- Migration help for your PBX or SBC, plus 24/7 incident response
Choose the provider that demonstrates secure configuration and transparent documentation, not just the one with the lowest quote.
Frequently Asked Questions
What is SIP trunking and how does it work?
SIP trunking is a virtual link between your business PBX and the public telephone network over the internet. It uses the SIP protocol to set up, manage, and end calls without physical phone lines.
What is the difference between SIP trunking and VoIP?
VoIP is the broad category of carrying voice over IP networks. SIP trunking is a specific service arrangement using the SIP protocol to connect your business phone system to outside telephone networks.
Is the SIP protocol encrypted?
Not automatically. TLS can encrypt SIP signaling, and SRTP separately protects the voice media itself. Without both enabled, some or all of your call traffic may travel unencrypted.
Is SIP trunking reliable?
Reliability depends on provider infrastructure, redundancy, internet quality, and support—not on SIP alone. Ask about failover testing and service commitments before you sign.


