As long as you are rouiting and terminating the inbound call on your pbx then it needn't be a security risk. However, it is easy to get it wrong and inadvertently give the external phone privileges you didn't intend (like maybe dialtone), or leaving a door open for someone else to use your system without your knowledge. If you can, then just get the remote phone to dial your inbound SIP-carrier number like everyone else. It's much safer.
Kind Regards
S