Any application accessible on an IP network is a potential security risk. SIP phones and servers are no exception: A number of vulnerabilities, affecting a long list of vendors, have been discovered; see www.cert.org/advisories/CA-2003-06.html.
At minimum, limit access to any SIP device. Also, purchase products from vendors that specialize in securing SIP. For example, SecureLogix Corp., which won our Well-Connected Product of the Year Award, is working on a device designed to secure SIP environments, and BroadSoft uses a product from Kagoor Networks to do the same.