Secure digital tools for Cameroon president remote work
What secure digital tools does Cameroon’s President Paul Biya need to work remotely?
The ability to review documents, consult advisors, issue directives or approve official acts from abroad is now technically feasible. However, when it comes to the President of the Republic, remote governance cannot rely on ordinary digital tools. It requires systems that guarantee the confidentiality of information, the identity of the decision-maker, the integrity of documents, and the traceability of every instruction.
The debate on remote governance was reignited after a statement by Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo. In a communiqué refuting claims of a “vacancy” at the highest level of state, he asserted that President Paul Biya continues to oversee files and issue directives—either in person or via “known electronic means.” This raises a critical question: what digital tools should a modern presidential administration use to receive, process, approve, and archive sensitive documents when the head of state is outside national territory?
Posting a decree on Facebook, X, or the official presidency website represents only the final step in public communication. It reveals nothing about the process through which the document was drafted, transmitted, reviewed, signed, recorded, and preserved.
Professional email under the @prc.cm domain
The first requirement is the systematic use of institutional email addresses linked to the official domain of the Presidency of the Republic.
All staff working with the head of state should be provided with personalized email accounts, such as [email protected], as well as functional addresses reserved for the General Secretariat, the Civil Cabinet, and other departments. For example, [email protected] should be prioritized.
Personal accounts like Gmail or Yahoo should never be used to transmit draft decrees, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The risk is not only technical—it lies in governance. A personal email account operates outside full state oversight: the administration cannot control its creation, the devices connected to it, message retention, recovery, or deactivation after a staff member leaves office.
A professional messaging system under the @prc.cm domain would enable the following:
- Creation and revocation of staff email accounts;
- Enforcement of strong authentication protocols;
- Preservation of official exchanges;
- Detection of suspicious connections;
- Prevention of automatic forwarding to personal inboxes;
- Implementation of a unified security and archiving policy.
Such a system must be protected against identity theft and phishing using mechanisms like SPF, DKIM, and DMARC. It should also enforce end-to-end encryption of server-to-server communications.
Even a well-protected institutional address should not be used to send highly sensitive documents as email attachments. Instead, it could notify the recipient that a file is available in a secure presidential platform.
A presidential platform for document management
The Presidency should deploy an electronic document management platform designed specifically for state affairs.
Each file on this platform should be registered with:
- A unique reference number;
- The identity of its author;
- A confidentiality level indicator;
- List of authorized users;
- Document version history;
- Comments and approvals;
- Date of validation;
- A complete access log.
This allows the President to consult a document from a secure terminal, add comments, request modifications, or approve a proposal—without the file being copied to multiple devices or sent through personal mailboxes.
For the most sensitive files, the platform should prevent local downloads, printing, text copying, or unauthorized transfers. It should also track who accessed the document, when, from which device, and what changes were made.
Electronic presidential signature with full verification
Remote validation of a decree or decision should not rely on a scanned image of the President’s signature.
A digital signature based on certified cryptographic keys would confirm:
- The identity of the signatory;
- The integrity of the document;
- The exact date and time of validation;
- The absence of post-signature alterations.
The cryptographic key used for the most critical acts should be stored in a highly secure hardware module—not on a regular computer, USB drive, or personal device. Its use should require direct authentication by the President and generate a time-stamped audit trail.
For major decisions, the process could include multiple layers: presidential approval, technical signature verification, legal review, official registration, and public dissemination.
Zero Trust architecture for remote access
A Virtual Private Network (VPN) can secure the connection between a traveling official and presidential servers, but it should not be the sole safeguard.
The Presidency could adopt a Zero Trust model—where no user, device, or network is trusted by default. Every access request would be verified based on multiple criteria:
- User identity;
- Device used;
- Geographic location of the connection;
- Document sensitivity level;
- User permissions;
- Behavioral patterns during the session.
Access to a presidential file could require the simultaneous use of an institutional device, a digital certificate, an encrypted connection, a physical security key, and a local biometric check on the terminal.
Exclusively institutional phones and computers
Presidential files must never be accessed from staff members’ personal phones.
Members of the Civil Cabinet, General Secretariat, and relevant departments should be equipped with devices owned and managed by the institution, administered by a dedicated technical team.
These devices must be:
- Fully encrypted;
- Regularly updated;
- Limited to authorized applications;
- Segregated from personal use;
- Remotely wiped if lost;
- Automatically locked after inactivity;
- Blocked from connecting to unsecured public Wi-Fi networks.
A centralized device management system would allow the administration to push updates, block dangerous apps, revoke devices, and remotely delete data in case of theft or compromise.
Anti-phishing authentication
A password—even a complex one—should never suffice to access presidential files.
Authentication should combine multiple factors:
- An authorized institutional device;
- A personal PIN;
- A physical security key;
- Potentially a local biometric scan.
While SMS-based codes can enhance security, they remain vulnerable to certain attacks. For highly sensitive accounts, physical keys and digital certificates offer superior resistance to phishing attempts.
Staff should also receive regular training to recognize fraudulent messages, urgent scams, malicious links, and impersonation attempts targeting senior officials.
WhatsApp: useful for alerts, not for transmitting files
WhatsApp is widely used in Cameroon, including within government agencies. Its end-to-end encryption protects message and call content in transit.
However, this does not qualify it as an official platform for managing presidential documents.
A file sent via WhatsApp remains exposed to risks such as:
- Loss or espionage of the device;
- Screenshots;
- Unauthorized forwarding;
- Syncing across linked devices;
- Inadequately protected backups;
- Use by former staff after departure.
WhatsApp alone also lacks the necessary tools for classifying documents, managing permissions, preserving versions, recording approvals, signing acts electronically, or ensuring proper archiving.
The app could be used to announce that a file is available, confirm a meeting, signal an emergency, or coordinate travel. For example:
“File reference PRC/SG/2026/125 is available in your secure workspace for review.”
The document itself should never be attached to the conversation.
The guiding principle: “Use WhatsApp to alert and coordinate; use the secure presidential platform to transmit, review, decide, sign, and archive.”
Secure government videoconferencing
Remote exchanges between the President and advisors could also go through a dedicated government videoconferencing solution.
Such a platform should support:
- End-to-end encryption of communications;
- Participant authentication;
- Strict control over invitations;
- Prohibition of unauthorized recordings;
- Retention of connection logs;
- Use of exclusively institutional terminals;
- Full control over data hosting.
Public links, free accounts, and unvetted apps should never be used for meetings involving defense, diplomacy, appointments, or government arbitration.
Classify documents by sensitivity level
Not all presidential documents carry the same risk. A classification policy could define four levels:
- Public: intended for public release;
- Internal: internal working documents;
- Confidential: whose disclosure could harm public action;
- Highly Sensitive: related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level determines the authorized transmission channel, authorized users, permissible devices, printing options, retention periods, and archiving procedures. A public document might be sent via professional email, but a highly sensitive file should only be accessible from a tightly controlled platform.
Full traceability of every decision
Every consultation, modification, approval, or transmission must be automatically logged.
The security journal should record:
- Who accessed the document;
- When they accessed it;
- From which device;
- What changes were made;
- Who approved the final version;
- When and by whom it was officially recorded and published.
A security operations center could detect unusual connections, mass document downloads, access from unrecognized devices, or unauthorized modifications to official acts.
This traceability would also help reconstruct events in the event of a leak, intrusion, or dispute over the authenticity of a decision.
Distinguish official decisions from social media posts
The Presidency’s Facebook and X accounts enable rapid public communication but must not be confused with the systems used to prepare and validate decisions.
Before a decree is posted online, it must follow a secure process:
- Transmitted through an authorized channel;
- Authenticated by the competent authority;
- Verified for integrity (no tampering);
- Time-stamped upon validation;
- Preserved in official archives.
A visible signature on a published image is not, in itself, sufficient digital proof. Security lies in the entire process leading up to publication.
Ten priority measures for the Presidency
To ensure secure remote governance, the Presidency could implement ten key actions:
- Mandate professional email under the @prc.cm domain;
- Ban personal accounts like Gmail or Yahoo for state business;
- Deploy a presidential electronic document management platform;
- Introduce a secure institutional electronic signature system;
- Provide exclusively professional phones and computers;
- Enforce multi-factor authentication resistant to phishing;
- Confine WhatsApp to alerts and coordination;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Provide regular training on espionage, phishing, and information leakage risks.
While no public evidence confirms that all these measures are currently in place at the Cameroonian Presidency, they represent the minimum security standards a state institution should adopt when handling remotely sensitive documents that impact finance, diplomacy, security, and national continuity.
These issues—secure document transmission, electronic signatures, data sovereignty, and digital continuity—will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, taking place from October 14 to 16, 2026, at the Palais des Congrès in Yaoundé. The event, organized under the high patronage of the Ministry of Posts and Telecommunications, will focus on the theme: “Artificial intelligence and e-governance: building effective public services in a cashless, paperless Africa.”
The question is not whether a president can work from Geneva, Paris, New York, or elsewhere. The real challenge is whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure that no one can alter, divert, or fabricate an act in the President’s name.
Modern tools and full traceability
Remote presidential work is not an insurmountable technological challenge. The true obstacle lies in the trust placed in tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must adopt modern tools, methods, and procedures so that every major decision leaves a clear trace: who posted what, approved what, when, through which channel, and with what security guarantees.