Cloud Communication Security: Risks, Controls & US Compliance

Cloud Communication Security: Risks, Controls & US Compliance

Since April 2025, the FBI has warned of AI-generated voice messages impersonating senior US officials. Attackers now target phone lines, video meetings, and ...

DEFEND MY BUSINESS
DEFEND MY BUSINESS
14 min read

Since April 2025, the FBI has warned of AI-generated voice messages impersonating senior US officials. Attackers now target phone lines, video meetings, and call recordings, not just email inboxes. Cloud communication security covers every control that protects these voice, video, and messaging channels. A misconfigured phone platform can expose recordings, customer data, and payment details.

The fix starts with knowing which risks apply and who owns each control. The sections below map voice-specific threats to named controls and named owners. They also explain cloud VoIP security for US businesses under HIPAA, PCI DSS, and CMMC. Each section ends with controls a business can verify with its provider.

What Is Cloud Communication Security and Who Is Responsible for It?

Cloud communication security protects voice, video, chat, and SMS traffic hosted by a third-party provider. These services run on platforms such as Microsoft Teams Phone, Zoom Phone, and RingCentral. Traffic crosses the public internet, so every network hop is a possible interception point. The scope includes stored data too, such as voicemail, call recordings, and transcripts. Messaging apps, meeting rooms, and fax-to-email gateways widen that scope further.

Security duties split between the provider and the customer under a shared responsibility model. The provider hardens data centers, networks, and core software, because only the provider controls them. The customer controls user accounts, admin settings, devices, and who can hear recordings. Amazon Web Services and Microsoft Azure publish the same split for their cloud platforms.

Misplaced assumptions about this split create security gaps. A provider certification does not cover weak passwords or over-shared recordings on the customer side. Teams comparing cloud communication solutions can map each duty before signing. The exact split varies by contract, so the service agreement is the final reference. Contracts also define breach notification timelines and data-location commitments.

Security areaProvider responsibilityCustomer responsibility
Data centers and networkPhysical security, redundancy, DDoS defensesNone
Platform softwarePatching, default encryptionEnabling optional security features
IdentitySSO and MFA supportEnforcing MFA, removing former staff
Call recordingsEncrypted storageAccess roles, retention periods
EndpointsSoftphone app updatesManaged devices, secure networks
ComplianceThird-party audit reportsUsing the platform in a compliant way

What Are the Biggest Cloud Communication Security Risks?

The biggest cloud communication security risks target identity, billing, and caller trust. Attackers favor these paths because stolen logins bypass encryption entirely. A valid SIP credential lets an attacker place calls as the business. Stolen credentials often come from phishing emails, reused passwords, or exposed admin portals. Encryption protects traffic in transit, but it cannot stop an authorized account from misuse.

Toll fraud turns a hijacked phone account into a direct billing loss. Attackers route calls to premium-rate international numbers they control, then collect a revenue share. This scheme is known as International Revenue Share Fraud, or IRSF. The victim business pays the carrier bill for every fraudulent minute. Country blocks and spend alerts limit how many minutes an attacker can bill.

Caller ID spoofing lets attackers display a trusted number on the victim's screen. The FCC responded by requiring STIR/SHAKEN in provider IP networks by June 30, 2021. STIR/SHAKEN signs calls so downstream carriers can verify the caller ID. Carriers assign attestation levels A, B, or C to each signed call. Signed caller ID does not stop vishing from legitimate, attacker-owned numbers.

ThreatHow it worksPrimary controlMain owner
Account takeoverStolen or reused passwordsPhishing-resistant MFA, SSOCustomer
Toll fraud (IRSF)Hijacked account dials premium numbersCountry blocks, spend alertsShared
Caller ID spoofingForged calling numberSigned calls, call analyticsProvider
AI voice vishingCloned voice requests access or moneyCallback verification, staff trainingCustomer
EavesdroppingUnencrypted SIP or RTP trafficTLS signaling, SRTP mediaShared
DDoS and SIP floodingTraffic overload drops callsDDoS mitigation SBC rate limitsProvider
Recording exposureOver-broad playback rightsRole-based access, retention limitsCustomer

How Cloud VoIP Security Works: Encryption and Session Border Controllers

Cloud VoIP security protects two separate streams: call signaling and call audio. SRTP and TLS divide the work between those two streams. TLS encrypts SIP signaling, typically on port 5061, which hides dialed numbers and credentials. SRTP, defined in IETF RFC 3711, encrypts the audio packets themselves. Unencrypted SIP on port 5060 exposes the same data in plain text.

Hop-by-hop encryption differs from end-to-end encryption in who can decrypt the audio. With hop-by-hop encryption, provider servers decrypt audio to record, transcribe, or bridge calls. Zoom and Microsoft Teams offer optional end-to-end modes that disable some of those features. Calls that reach the public telephone network cannot remain end-to-end encrypted. Buyers handling privileged legal or medical calls can weigh that trade-off per call type.

FactorHop-by-hop (TLS and SRTP)End-to-end
Who can decryptProvider serversCall participants only
Recording and transcriptionSupportedUsually disabled
Calls to regular phone numbersSupportedNot possible
Typical useStandard business callingSensitive internal calls

A session border controller acts as a SIP-aware firewall at the network edge. Standard firewalls cannot read SIP messages, so they miss voice-specific attacks. SBCs hide internal IP addresses, limit call rates, and block unauthorized international routes. Businesses using SIP trunking or business VoIP need to confirm who operates the SBC. Hybrid setups that keep an on-premise PBX add a customer-side SBC at the edge.

UCaaS Security Controls for Users, Devices, and Recordings

UCaaS security starts with identity, because one login unlocks calls, chats, and files. NIST SP 800-207 defines a zero trust model that verifies every user and device. Single sign-on through Okta or Microsoft Entra ID centralizes that verification. Conditional access policies can block logins from unmanaged devices or unexpected countries. Zero trust access tools extend the same checks to softphones on remote networks. 

NIST SP 800-63B-4, finalized in 2025, sets current US authentication guidance. It bars forced periodic password changes unless there is evidence of compromise. It also sets a 15-character minimum when a password is the only factor. Phishing-resistant methods, such as FIDO2 security keys, resist credential phishing by design. Microsoft, Google, and Okta all support FIDO2 passkeys for workforce sign-in.

Contact center security focuses on recordings, transcripts, and agent access. Recordings often capture payment details, health data, and identity answers. Role-based access limits playback to staff who need it. Audit logs then record who played or downloaded each file. A cloud contact center handling card payments also falls under PCI DSS rules.

  • Enforce MFA for every user, with stronger factors for admins.
  • Remove departed employees' accounts on their last working day.
  • Restrict international calling to approved countries only.
  • Set spend or concurrent-call limits on each trunk.
  • Encrypt recordings at rest and set retention periods.
  • Replace default voicemail PINs with unique PINs per user.
  • Review admin audit logs on a fixed schedule.

How to Choose a Secure Cloud Communication Platform for US Compliance

A secure cloud communication platform proves its controls through independent audits, not marketing claims. Audit reports, contract terms, and data-location details reveal what a provider actually guarantees. SOC 2 reports are restricted-use documents, so providers typically share them under NDA. Cloud communication security duties under US law differ by industry and data type. The right evidence depends on whether calls carry health, payment, financial, or defense data.

HIPAA compliant VoIP requires a signed Business Associate Agreement when the provider stores health data. HHS limits the conduit exception to transmission-only services with transient access. Voicemail, recordings, and transcripts count as stored data, not transient transmission. Business associates have faced direct HIPAA liability since the 2013 Omnibus Rule. HIPAA compliance reviews confirm the agreement matches the services actually used.

A SOC 2 Type II report tests whether controls worked over a review period. Type I reports, under the same AICPA framework, check design at one moment only. Federal agencies require FedRAMP authorization for the cloud services they use. Defense contractors handling CUI face CMMC compliance under 32 CFR Part 170. That program rule took effect on December 16, 2024.

Rule or frameworkApplies toWhat to ask the provider
HIPAAHealthcare covered entities and business associatesSigned BAA covering voice, recordings, transcripts
PCI DSSBusinesses taking card payments by phoneRecording pause or DTMF masking, no CVV retention
GLBA Safeguards RuleFinancial institutions under FTC oversightEncryption, access logs, vendor oversight terms
CMMCDoD contractors handling FCI or CUIFedRAMP Moderate or equivalent for CUI data
FedRAMPFederal agencies and their cloud vendorsCurrent FedRAMP authorization status
SOC 2Any buyer wanting audited controlsLatest Type II report and bridge letter

Cloud Communication Security Best Practices Checklist

Cloud communication security best practices work best as a repeatable checklist, not a one-time project. Provider features, staff, and attack methods change over time, so controls drift. The sequence below moves from identity to monitoring to testing. Regulated firms can map each step to HIPAA, PCI DSS, or CMMC evidence.

  1. Inventory every number, trunk, user, and integration on the platform.
  2. Enforce phishing-resistant MFA and single sign-on for all accounts.
  3. Block international destinations the business never calls.
  4. Set concurrent-call and spend alerts on each SIP trunk.
  5. Confirm TLS signaling and SRTP media on every device and trunk.
  6. Restrict recording access by role and set retention limits.
  7. Pause recording or use DTMF masking during card payments.
  8. Verify payment or access requests through a callback to a known number.
  9. Review admin and call-detail logs weekly for unusual patterns.
  10. Run penetration tests on voice systems at least once a year.

Penetration tests find weaknesses that configuration reviews miss, such as exposed SIP ports. Test scope can include SIP trunks, SBC configurations, softphone apps, and admin portals. PCI DSS requires penetration testing at least every 12 months and after significant changes. Firms outside PCI scope can adopt the same 12-month cycle as a baseline. Penetration testing and managed cloud security services can cover the gaps between formal tests.

Final Takeaways for Securing Business Voice and Video

Cloud communication security now covers identity, fraud, caller trust, and compliance, not only encryption. The provider secures the platform, while the business secures accounts, recordings, and settings. FCC caller ID rules, NIST SP 800-63B-4, and CMMC now shape voice system security. As AI voice cloning spreads, verification procedures carry as much weight as encryption.

More from DEFEND MY BUSINESS

View all →

Similar Reads

Browse topics →

More in Health

Browse all in Health →

Discussion (0 comments)

0 comments

No comments yet. Be the first!