Secure digital tools for Cameroon’s president working remotely

Cameroon – Accessing files from abroad, exchanging with collaborators, issuing instructions, or approving administrative acts is technically feasible today. However, when it comes to the President of the Republic, remote work cannot rely on ordinary digital tools. It requires systems capable of ensuring information confidentiality, decision-maker identity verification, document integrity, and traceability of every instruction.
The debate on remote governance was reignited by a statement from the Minister of State for Higher Education, Professor Jacques Fame Ndongo. In a communiqué denying claims of a “vacancy” at the top of the state, he confirmed that President Paul Biya continues to oversee files and issue directives—either in person or through “electronic means known to all.”
This declaration raises a critical question: what digital tools should a modern presidential administration use to receive, review, approve, and archive sensitive documents when the head of state is outside national territory?
Publishing a decree on Facebook, X, or the official presidency website is merely the final step in public communication. It reveals nothing about how the document was prepared, transmitted, examined, signed, recorded, or preserved.
Institutional email under the @prc.cm domain
The first requirement should be the systematic use of official email addresses linked to the Presidency’s domain. Collaborators must have personalized addresses like [email protected], along with functional accounts for the General Secretariat, Civil Cabinet, and other departments—such as [email protected], which should be prioritized.
Personal accounts like Gmail or Yahoo must never be used for transmitting draft decrees, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The issue isn’t just the technical security of these platforms but their governance: personal accounts fall partially outside state control regarding creation, device access, message storage, recovery, or deactivation after an official’s departure.
A professional email system under @prc.cm would enable:
- Creation and revocation of collaborator accounts;
- Enforcement of multi-factor authentication;
- Preservation of official exchanges;
- Detection of suspicious logins;
- Blocking automatic transfers to personal inboxes;
- Implementation of unified security and archiving policies.
This system must guard against identity theft and phishing using SPF, DKIM, and DMARC protocols while enforcing server-to-server encryption. Even with a secure institutional address, sensitive documents should never be sent as attachments. Instead, recipients should be notified that a file is available in a secure presidential platform.
A presidential platform for document management
The Presidency requires an electronic document management platform tailored for state affairs. Each file should be registered with:
- A unique reference;
- The author’s identity;
- Confidentiality level;
- Authorized viewers;
- Document versions;
- Comments and arbitrations;
- Approval date;
- Complete access history.
The head of state could then review documents from a secure terminal, add observations, request modifications, or approve proposals without files being copied across devices or sent to personal mailboxes. For highly sensitive files, the platform should prevent local downloads, printing, text copying, or unauthorized transfers.
It should also track who accessed the document, when, from which device, and what changes were made—ensuring full transparency in the decision-making process.
Verifiable presidential electronic signatures
Remote validation of decrees or decisions must not rely on scanned images of a signature. Instead, electronic signatures based on digital certificates should verify:
- The signatory’s identity;
- Document integrity;
- Validation date and time;
- Absence of post-signature modifications.
Cryptographic keys for signing critical acts must be stored in highly secure hardware modules—not on ordinary computers, USB drives, or personal phones. Any use of these keys should require direct presidential authentication and generate a timestamped log.
For major decisions, the process could include multiple layers: presidential validation, technical signature verification, legal review, official recording, and then publication.
Zero Trust-based remote access
A Virtual Private Network (VPN) can secure connections between officials abroad and presidential servers—but it shouldn’t be the sole safeguard. The Presidency should adopt a Zero Trust architecture, assuming no user, device, or network is inherently trustworthy. Access requests would be verified based on:
- User identity;
- Device used;
- Connection location;
- Document sensitivity level;
- Assigned permissions;
- Observed connection behavior.
Accessing a presidential file could require an institutional computer, digital certificate, encrypted connection, physical security key, and local biometric verification simultaneously.
Exclusively institutional phones and computers
Presidential files must never be reviewed on collaborators’ personal devices. Civil Cabinet members, General Secretariat staff, and other officials handling such documents should use equipment owned and administered by the institution. These devices must be:
- Fully encrypted;
- Regularly updated;
- Restricted to authorized applications;
- Segregated from personal use;
- Remotely erasable if lost;
- Automatically locked after inactivity;
- Prohibited from connecting to unsecured public Wi-Fi networks.
A centralized device management solution would allow the administration to install updates, block risky applications, revoke devices, and wipe data remotely in case of theft or compromise.
Phishing-resistant authentication
A password—even a complex one—should never suffice for accessing presidential files. Authentication must combine:
- An institutional device;
- A personal code;
- A physical security key;
- Local biometric verification (if applicable).
SMS codes can enhance security but remain vulnerable to certain attacks. For highly sensitive accounts, physical keys and digital certificates offer superior phishing resistance. Collaborators should also be trained regularly to recognize fraudulent messages, urgent scams, malicious links, and attempts to impersonate superiors.
WhatsApp: useful for alerts, not for file transfers
WhatsApp is widely used in Cameroon, including within administrations, thanks to its end-to-end encryption. However, this doesn’t make it an official platform for handling presidential documents. Sending a file via WhatsApp risks exposure through:
- Lost or compromised phones;
- Screenshots;
- Unauthorized transfers;
- Linked devices;
- Inadequately protected backups;
- Personal phones of former collaborators.
WhatsApp also lacks mechanisms for document classification, access management, version control, validation recording, electronic signing, or administrative archiving. It could, however, be used to alert collaborators that a file is available in a secure presidential space—such as: “The document referenced PRC/SG/2026/125 is now accessible in your secure workspace for review.” The file itself should never be attached.
The rule is simple: Use WhatsApp for alerts and coordination; rely on the secure presidential platform for transmission, review, decision-making, signing, and archiving.
Secure government videoconferencing solutions
Remote exchanges between the president and collaborators should use dedicated government videoconferencing platforms offering:
- Encrypted communications;
- Participant identification;
- Strict invitation controls;
- Prohibition of unauthorized recordings;
- Connection logs retention;
- Exclusive use of institutional devices;
- Data hosting control.
Public links, free accounts, and unvetted applications must never be used for meetings involving defense, diplomacy, appointments, or government arbitrations.
Classifying documents by sensitivity level
Not all presidential documents carry the same risk. A classification policy could define four categories:
- Public: documents intended for dissemination;
- Internal: working documents reserved for state services;
- Confidential: documents whose disclosure could harm public action;
- Highly sensitive: files related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level determines the authorized transmission channel, authorized personnel, permissible devices, printing options, retention periods, and archiving methods. A public document might be sent via professional email, but a highly sensitive file must remain accessible only through a tightly controlled platform.
Comprehensive traceability of every decision
Every consultation, modification, validation, or transmission must be automatically logged. The security journal should specify:
- Who accessed the document;
- When they accessed it;
- From which device;
- What changes were made;
- Who approved the final version;
- When the document was recorded and published, and by whom.
A security operations center could detect unusual logins, massive document downloads, access attempts from unrecognized devices, or abnormal modifications to official acts. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over a decision’s authenticity.
Distinguishing official decisions from social media posts
Presidency Facebook pages and X accounts enable rapid public communication but must not be confused with the systems used to prepare and validate decisions. Before a decree is published online, it must follow a strict process:
- The document was transmitted through an authorized channel;
- The competent authority was authenticated;
- The final version was unaltered;
- The validation was timestamped;
- The original is preserved in official archives.
A signature visible on an online image is not, by itself, sufficient digital proof. Security depends on the complete process preceding publication.
Ten priority measures for the Presidency
The Presidency could implement ten critical actions:
- Mandate professional email under the @prc.cm domain;
- Ban personal accounts like Gmail or Yahoo for state affairs;
- Deploy a presidential electronic document management platform;
- Introduce secure institutional electronic signatures;
- Provide exclusively professional phones and computers;
- Enforce multi-factor authentication resistant to phishing;
- Limit WhatsApp to alerts and coordination;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Train collaborators regularly on espionage, phishing, and information leakage risks.
No public information confirms whether Cameroon’s Presidency currently uses all these measures. However, they represent the minimum safeguards a state institution must adopt when handling remotely sensitive files that impact finances, diplomacy, security, and national continuity.
These challenges—secure document transmission, electronic signatures, data sovereignty, and digital continuity—will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, at the Yaoundé Congress Palace. The event, organized under the high patronage of the Ministry of Posts and Telecommunications, will focus on the theme: “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa.”
The question isn’t merely whether a president can work from Geneva, Paris, or New York. The core issue is whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in the president’s name.
Modern tools and traceability
Remote presidential work isn’t an insurmountable technological challenge. The real hurdle lies in trusting the tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must adopt modern tools, methods, and procedures to ensure every critical decision leaves a trace: who posted what, validated what, when, through which channel, and with what security guarantees?
