July 31, 2026

Ouaga Press

Independent English-language coverage of Burkina Faso's most pressing news and developments.

Secure digital tools for Cameroon’s president to work remotely

In today’s digital age, accessing files from abroad, communicating with teams, and approving administrative documents is technically feasible for most professionals. Yet when it comes to the head of state, remote governance cannot rely on standard digital tools. It demands systems capable of ensuring the confidentiality of sensitive information, verifying the identity of decision-makers, maintaining document integrity, and tracking every instruction throughout its lifecycle.

The debate on remote governance gained momentum following a statement by Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo. Addressing concerns about a potential ‘vacancy’ at the highest level of government, he asserted that President Paul Biya continues to oversee operations and issue directives, both in person and through ‘electronic means known to all.’ While his remarks addressed political discourse, they also raised a critical question: what secure digital infrastructure should Cameroon’s presidency deploy to receive, review, verify, and archive classified documents when the head of state is outside national borders?

Posting a decree on social media or a government website represents just the final step in public communication. It reveals nothing about how the document was prepared, transmitted, examined, signed, registered, or preserved.

Institutional email under the @prc.cm domain

The first priority is implementing institutional email addresses linked to the official presidency domain. Members of the presidential team should use personalized addresses, such as [email protected], along with functional accounts for the General Secretariat, Civil Cabinet, and other key departments. For instance, [email protected] should serve as the primary contact for official correspondence.

Personal accounts from providers like Gmail or Yahoo are unsuitable for handling presidential documents, including draft decrees, confidential memos, appointment files, diplomatic correspondence, or state directives. The risk goes beyond technical security limitations—state authorities lose control over account creation, device access, message storage, and deactivation after staff departures.

An institutional mail system under @prc.cm would enable authorities to:

  • Create and revoke staff accounts as needed;
  • Enforce multi-factor authentication;
  • Preserve official exchanges;
  • Detect suspicious login attempts;
  • Block automatic forwarding to personal inboxes;
  • Apply uniform security and archiving policies.

Such a system should incorporate anti-phishing measures like SPF, DKIM, and DMARC protocols, along with end-to-end encryption between servers. Even with robust institutional email, highly sensitive files should not be sent as attachments. Instead, the system might notify recipients that a document is available in a secure presidential portal.

A presidential platform for secure document management

The presidency requires a dedicated electronic document management system tailored to state affairs. Each file should be logged with:

  • A unique identifier;
  • The author’s identity;
  • A confidentiality classification;
  • Authorized users;
  • Document versions;
  • Comments and approvals;
  • Validation date;
  • A complete access history.

This setup would allow the president to review documents from a secure terminal, add remarks, request revisions, or approve proposals without files being copied across devices or sent to private email accounts. For highly sensitive materials, the platform should prevent local downloads, printing, text copying, or unauthorized transfers.

It should also log who accessed a document, when, from which device, and what modifications were made. A security operations center could then detect unusual activity, such as unauthorized access attempts or bulk document downloads.

Verifiable electronic signatures for presidential decrees

Remote validation of decrees or decisions must rely on more than a scanned image of the president’s signature. A qualified electronic signature using digital certificates would verify:

  • The signatory’s identity;
  • The document’s integrity;
  • Date and time of validation;
  • Absence of post-signature alterations.

The cryptographic key for signing critical documents should be stored in a tamper-proof hardware module—not on a standard computer, USB drive, or personal phone. Any use of this key should require direct presidential authentication and generate a timestamped audit trail.

For major decisions, the process could involve multiple layers of verification: presidential approval, technical signature validation, legal review, official registration, and public release.

Zero Trust principles for secure remote access

A virtual private network (VPN) can secure connections between traveling officials and presidential servers, but it should not be the sole safeguard. Adopting a Zero Trust architecture means no user, device, or network is trusted by default. Access requests should be evaluated based on:

  • User identity;
  • Device authenticity;
  • Location of connection;
  • Document sensitivity level;
  • User permissions;
  • Behavioral patterns during the session.

Accessing a presidential file might require an institutional computer, digital certificate, encrypted connection, physical security key, and a local biometric verification on the device itself.

Exclusively institutional devices for presidential staff

Presidential documents must never be viewed on personal phones or computers. Civil Cabinet members, the General Secretariat, and other officials handling sensitive files should use institutionally owned and managed devices. These terminals should be:

  • Fully encrypted;
  • Regularly updated with security patches;
  • Restricted to authorized applications;
  • Segregated from personal use;
  • Remotely wipeable in case of loss;
  • Automatically locked after inactivity;
  • Prohibited from connecting to unsecured public Wi-Fi networks.

A centralized device management system would allow administrators to install updates, block dangerous apps, revoke devices, and erase data remotely in the event of theft or compromise.

Anti-phishing authentication for maximum security

A complex password alone is insufficient for accessing presidential files. Multi-factor authentication should combine:

  • An institutional device;
  • A personal PIN;
  • A physical security key;
  • Optional local biometric verification.

While SMS codes can enhance security, they remain vulnerable to certain attacks. For the most sensitive accounts, physical keys and digital certificates offer superior resistance to phishing attempts. Staff should also receive regular training to recognize fraudulent messages, urgent scams, malicious links, and impersonation attempts targeting senior officials.

WhatsApp: useful for alerts, not for sensitive files

WhatsApp is widely used in Cameroon, even within government circles, thanks to its end-to-end encryption. However, its protections do not qualify it as an official document management platform. A file shared via WhatsApp remains exposed through:

  • The loss or compromise of a phone;
  • Screenshots or unauthorized forwarding;
  • Unsecured backups;
  • Personal devices of former officials;

WhatsApp lacks the features needed to classify documents, manage permissions, track versions, validate decisions, or ensure proper archiving. It can, however, serve to notify users that a document is ready in a secure portal—for example: ‘The file PRC/SG/2026/125 is available in your secure workspace for review.’ The actual document should never be attached to the message.

Secure government videoconferencing solutions

Remote exchanges between the president and collaborators should occur through dedicated, government-grade videoconferencing platforms that provide:

  • End-to-end encryption;
  • Participant authentication;
  • Strict invitation controls;
  • Protection against unauthorized recordings;
  • Connection logging;
  • Use of institutional devices only;
  • Data hosting under national jurisdiction.

Public links, free accounts, and unvetted applications have no place in meetings concerning defense, diplomacy, appointments, or government arbitrations.

Classifying documents by sensitivity level

Not all presidential documents carry the same risk. A classification policy could define four tiers:

  • Public: intended for dissemination;
  • Internal: reserved for government services;
  • Confidential: disclosure could harm public action;
  • Highly sensitive: related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each level determines the authorized transmission channel, permitted users, device restrictions, printing permissions, retention duration, and archiving procedures. A public document might be sent via institutional email, while a highly sensitive file should only be accessible through a highly controlled portal.

Maintaining a complete audit trail of every decision

Every consultation, alteration, validation, or transmission should be automatically recorded, with logs specifying:

  • Who accessed the document;
  • When and from which device;
  • What modifications were made;
  • Who approved the final version;
  • When the document was registered and published, and by whom.

A security operations center could flag unusual behavior, such as atypical login patterns or bulk data exfiltration attempts. This traceability would also help reconstruct events in the event of a leak, intrusion, or dispute over the authenticity of a decision.

Distinguishing between official decisions and social media posts

Presidential Facebook pages and X accounts allow rapid public communication, but they are not the systems used to prepare and validate decisions. Before a decree is published online, it must follow a secure process:

  • Transmission through authorized channels;
  • Authentication of the competent authority;
  • Verification that the final version is unaltered;
  • Timestamped validation;
  • Preservation of the original in official archives.

An image of a signature posted online is not, in itself, sufficient digital proof. Security lies in the entire process that precedes publication.

Ten priority measures for the presidency

To modernize remote governance, the presidency could implement ten essential actions:

  1. Mandate the use of institutional email under the @prc.cm domain;
  2. Ban personal Gmail, Yahoo, and similar accounts for state business;
  3. Deploy a dedicated presidential electronic document management platform;
  4. Introduce secure institutional electronic signatures;
  5. Provide exclusively institutional phones and computers to staff;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Limit WhatsApp to alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security operations center;
  10. Train staff regularly on espionage, phishing, and information leakage risks.

While no public evidence confirms that Cameroon’s presidency currently uses all these measures, they represent the minimum standards required for an institution handling remotely sensitive documents that impact national finances, diplomacy, security, and continuity of state functions.

These imperatives—secure document transmission, electronic signatures, data sovereignty, and digital continuity—will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, at the Palais des Congrès in Yaoundé. Under the theme ‘Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa,’ the event will convene public decision-makers, development agencies, government institutions, businesses, experts, and private sector actors from across the continent.

The core question is not whether a president can work from Geneva, Paris, New York, or elsewhere. The real challenge lies in whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in the president’s name.