Are VoIP Calls Secure? Let’s Talk About Who Could Be Listening

For something that most of use all day, the office phone gets off remarkably lightly. We worry about phishing attempts in dodgy emails and who can access company accounts – and then proceed to spend twenty minutes on a call discussing a customer’s financial situation over a headset.

Since October is Cybersecurity Awareness Month, let’s give the office phone a bit of attention for a change. Even though it feels like a private conversation between two people, there’s still technology involved and it needs just as much security as anything else in the office.

Voice over Internet Protocol (VoIP) uses an Internet connection to make voice and video calls and on the whole, it is fairly secure. Especially if you’re using a reputable provider who prioritises security. Naturally, there’s no blanket guarantee though. Other factors like who your provider is, how the system is configured and your own habits can all affect the security of your calls.

 

Who Can Hear Your Side Of The Story?

 

VoIP may sound like a rather complicated piece of technology, but all it does in a nutshell is convert speech into digital data and carries it across a network. You can choose to speak through a desk phone or an app on your laptop but the principle is much the same.

The security concern with VoIP is whether someone could successfully intercept that data while it’s travelling and figure out what it means. Reputable providers will use end-to-end encryption so that the data is scrambled while it’s on the move. Even if someone were to access the traffic, it doesn’t mean that they can automatically gain access to the conversation.

You may see providers mention things like TLS and SRTP which, to most people, doesn’t carry a whole lot of meaning. Broadly, TLS can protect the messages that establish and manage a call, while SRTP protects the audio itself. They’re absolutely useful to have but end-to-end encryption is what you want. It’s one step further than just encryption which can protect the connection between your device and the provider, but the provider’s systems will still be able to process the audio.

Something else to consider is the destination of your call. According to Microsoft’s encryption guidance, Teams end-to-end encryption isn’t available for calls that involve the public switched telephone network (PSTN). However, the PSTN will be retired as of 31 January 2027 so this won’t affect calls in the future.

What you can do is ask your provider what happens on the calls that you make, including any stages outside its own network so you can be aware of the limits.

 

 

A Call Recording Has A Life Of Its Own

 

Call recording is often one of the features available with VoIP and it’s absolutely useful for training purposes or to keep track of calls for customer profiles. These recordings and transcripts can remain accessible for months long after the conversation has finished. It’s not so handy though if more people can access it than you initially thought.

Your provider should be willing to be upfront with you about who can play, download or share the recordings, where they’re stored and when they are deleted. If they’re hesitant to share this information with you, well, that’s a bit of a red flag on it’s own and you should probably look into alternative providers.

 

Your Phone Bill Can Indicate Something Is Wrong

 

While the majority of cyber criminals target phone systems with the intention of gaining access to confidential information, listening in isn’t the only reason they do it. Sometimes, their goal is to use your service to make costly international or premium-rate calls – which means your monthly bill will skyrocket. In fact, the National Cyber Security Centre has reported thousands of calls falling victim to dial-through fraud.

For a small business, seeing that number on your bill could ruin considerably more than Monday morning. To be on the safe side, you can set unusual-usage alerts on your VoIP system and even go one step further by blocking destinations that nobody in your company needs to call. It’s also worth double-checking your contract’s fraud provisions before you get to a dispute about who is liable to pay.

Phishing can also happen through a phone call where someone rings you, sounding so convincing, telling you that there’s an issue with your system and they need codes or passwords to fix it. Encryption can’t help you in that situation if you verbally hand over information and a familiar number doesn’t provide much reassurance since Caller ID can be faked. In this case, it’s better to hang up and call the official number on the company’s website to see if the issue really does exist.

 

A Little Upkeep Can Go A Long Way

 

If you haven’t secured your phone system or if it’s been a while, make the time to put together a little to-do list. Always use strong, unique passwords with multi-factor authentication or passkeys if the option is available. The NSCSC’s account-security guidance also recommends removing any accounts that are no longer needed.

Maintenance is also something that has to be ongoing, especially if security is your biggest concern. That means having someone regularly update all apps, handsets and routers and to be quick to check any suspicious activity alerts that come through. If this is done by your provider, it’s worth finding out from them exactly what they cover and what still falls under your responsibility to do – it will save finger pointing down the line should an issue arise.

If you know exactly what protects your calls and ensure that those are maintained on a regular basis, you should be able to use your VoIP system with full confidence.