At Astricon in Atlanta I presented the initial results of our VOIP Security Audits, and we will be posting links to both the presentation and the video when it is made available.

Here is one of the findings that were presented:
* The average number of Server and OS critical problems was 18.6 problems per PBX
* The highest number of Server and OS critical problems found was 117 problems on a single PBX

Conclusion:
You need to have an update policy with regular security updates for the server, not just the Asterisk software, and it needs to be implemented.

Click on this link to get more information about the GreenfieldTech VOIP Security Audits