Cameroon’s presidential work abroad: what secure digital tools are needed?
The ability to review files, exchange with collaborators, issue instructions or approve administrative acts remotely is now technically feasible. However, when the head of state is involved, the continuity of remote work cannot rely on ordinary digital tools. It requires systems capable of ensuring the confidentiality of information, the authenticity of the decision-maker, the integrity of documents, and the traceability of every instruction.
The debate on remote governance was reignited by a statement from the Minister of Higher Education, Professor Jacques Fame Ndongo. In a communiqué rejecting claims of a “vacancy” at the top of the state, he asserted that President Paul Biya continues to oversee files and issue directives, either in person or through “electronic means known to all.” This raises a critical question: what digital tools should a modern presidential administration use to receive, examine, approve, and archive sensitive documents when the head of state is abroad?
Publishing a decree on Facebook, X, or the official presidency website represents only the final step in public communication. It does not reveal the process through which the document was prepared, transmitted, reviewed, signed, recorded, and preserved.
Mandatory institutional email addresses under the @prc.cm domain
The first requirement should be the systematic use of official email addresses linked to the Presidency’s domain. Collaborators must have personalized addresses, such as [email protected], as well as functional addresses reserved for the General Secretariat, Civil Cabinet, and other services—like [email protected], which should be prioritized.
Personal accounts such as Gmail or Yahoo should never be used to transmit draft decrees, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The issue is not merely the technical security capabilities of these platforms but the governance surrounding their use. Personal accounts fall partially outside the administration’s control: the state does not always manage their creation, the devices connected to them, message retention, recovery, or deactivation upon a staff member’s departure.
A professional messaging system under @prc.cm would enable:
- Creating and revoking collaborator accounts;
- Enforcing strong authentication;
- Preserving official exchanges;
- Detecting suspicious logins;
- Preventing automatic forwarding to personal inboxes;
- Applying uniform security and archiving policies.
This messaging system must be protected against identity theft and phishing using mechanisms like SPF, DKIM, and DMARC, with encrypted communication between servers. However, even a well-secured institutional address is not suitable for sending highly sensitive documents as simple attachments. Instead, it could notify the recipient that a file is available in a secure presidential platform.
A presidential platform for document management
The Presidency should have an electronic document management platform specifically designed for state affairs. Each file could be recorded with:
- A unique reference;
- The identity of its author;
- Its confidentiality level;
- Authorized personnel for access;
- Different versions of the document;
- Comments and arbitrations;
- Validation date;
- A complete access history.
This would allow the head of state to consult a document from a secure terminal, add observations, request modifications, or approve a proposal without the file being copied across multiple devices or sent to personal mailboxes. For highly sensitive files, the platform should prevent local downloads, printing, text copying, or unauthorized transfers. It should also track who accessed the document, when, from which device, and what changes were made.
A verifiable electronic presidential signature
Remote validation of a decree or decision should not rely on a simple scanned image of the president’s signature. An electronic signature based on digital certificates would verify:
- The identity of the signatory;
- The integrity of the document;
- The date and time of validation;
- That no modifications were made after signing.
The cryptographic key used for signing the most critical acts should be stored in a highly secure hardware module—not on a regular computer, USB drive, or personal phone. Any use of this key should require direct authentication from the head of state and generate a timestamped trace. For major decisions, the process could include multiple checks: presidential validation, technical signature verification, legal review of the act, official recording, and then publication.
Zero Trust architecture for remote access
A virtual private network (VPN) can secure the connection between a traveling official and the presidency’s servers, but it should not be the only safeguard. The Presidency could adopt a Zero Trust architecture, where no user, device, or network is trusted by default. Every access request would be verified based on multiple factors:
- The user’s identity;
- The device used;
- The location of the connection;
- The sensitivity level of the document;
- The permissions granted to the official;
- The observed behavior during the session.
Access to a presidential file might require an institutional computer, a digital certificate, an encrypted connection, a physical security key, and a local biometric check on the device.
Exclusively institutional phones and computers
Presidential files should never be accessed from collaborators’ personal phones. Members of the Civil Cabinet, General Secretariat, and relevant services must use equipment and mobile terminals owned by the institution and managed by a specialized team. These devices should be:
- Fully encrypted;
- Regularly updated;
- Limited to authorized applications;
- Separated from personal use;
- Remotely erasable in case of loss;
- Automatically locked after a short period of inactivity;
- Restricted from connecting to unsecured public Wi-Fi networks.
A centralized terminal management solution would allow the administration to install updates, block dangerous apps, revoke devices, and remotely delete data in case of theft or compromise.
Phishing-resistant authentication
A password, even complex, should never suffice for accessing Presidency files. Authentication should combine multiple elements:
- An institutional device;
- A personal code;
- A physical security key;
- Possibly a local biometric check.
Codes sent via SMS can enhance security but remain vulnerable to certain attacks. For highly sensitive accounts, physical keys and digital certificates offer better resistance to phishing attempts. Staff should also be regularly trained to recognize fake messages, fraudulent urgent requests, malicious links, and attempts to impersonate superiors.
WhatsApp for alerts, not for document transmission
WhatsApp is widely used in Cameroon, even within administrations, thanks to its end-to-end encryption. However, this does not make it an official platform for managing presidential documents. A file sent via WhatsApp could still be exposed if the phone is lost, through screenshots, unauthorized transfers, or backups on personal devices. WhatsApp also lacks the mechanisms needed to classify files, manage access permissions, preserve versions, record validations, or ensure administrative archiving.
The app could be used to announce that a file is available, confirm a meeting, signal an urgency, or coordinate travel, but the document itself should never be attached. The rule is simple: WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision-making, signing, and archiving.
Secure government videoconferencing
Remote exchanges between the president and collaborators could also use a dedicated government videoconferencing platform. This solution should enable:
- Encrypted communications;
- Participant identification;
- Strict control of invitations;
- Prohibition of unauthorized recordings;
- Retention of connection logs;
- Use of exclusively institutional terminals;
- Control over data hosting.
Public links, free accounts, and unvetted applications should never be used for meetings involving defense, diplomacy, appointments, or government arbitrations.
Classifying documents by sensitivity
Not all Presidency documents carry the same risk. A classification policy could define four categories:
- Public: Documents intended for dissemination;
- Internal: Working documents reserved for state services;
- Confidential: Documents whose disclosure could harm public action;
- Highly sensitive: Documents related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level would determine the authorized transmission channel, permitted personnel, usable devices, printing options, retention duration, and archiving procedures. A public document could be sent via professional messaging, while a highly sensitive file should remain accessible only through a tightly controlled platform.
Complete traceability for every decision
Every consultation, modification, validation, or transmission should be automatically recorded. The security log should detail:
- Who accessed the document;
- When they accessed it;
- From which device;
- What changes were made;
- Who validated the final version;
- When the document was recorded and published, and by whom.
A security operations center could detect unusual logins, massive document downloads, access attempts from unrecognized devices, or abnormal modifications to official acts. This traceability would also help reconstruct events in case of a leak, intrusion, or dispute over the authenticity of a decision.
Distinguishing official decisions from social media posts
Presidency Facebook pages and X accounts are useful for rapidly informing the public, but they must not be confused with the systems used to prepare and validate decisions. Before a decree is shared on social media, it must follow a process:
- The document was transmitted through an authorized circuit;
- The competent authority was authenticated;
- The final version was not altered;
- The validation was timestamped;
- The original is preserved in official archives.
A visible signature on an online image alone does not constitute full digital proof. Security lies in the complete process preceding publication.
Ten priority measures for the Presidency
The Presidency could implement ten key actions:
- Make professional messaging under the @prc.cm domain mandatory;
- Ban personal Gmail, Yahoo, and similar accounts for state affairs;
- Deploy a presidential electronic document management platform;
- Introduce a secure institutional electronic signature system;
- Provide exclusively professional phones and computers;
- Enforce phishing-resistant multi-factor authentication;
- Reserve WhatsApp for alerts and coordination;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Regularly train staff on espionage, phishing, and information leakage risks.
While no public evidence confirms that the Cameroonian Presidency currently uses all these measures, they represent the minimum guarantees a state institution should strive for when handling remote files critical to finance, diplomacy, security, and national continuity.
These challenges—secure file transmission, electronic signatures, data sovereignty, and digital continuity of the state—will take center stage at E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, at the Yaoundé Congress Palace. The event, held under the high patronage of the Ministry of Posts and Telecommunications, will focus on the theme: “artificial intelligence and e-governance: building efficient public services in a cashless and paperless Africa.“
The question is not merely whether a president can work from Geneva, Paris, New York, or another location. The essential challenge is determining whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in the president’s name.
Modern tools and traceability
Remote presidential work is not an insurmountable technological problem. The real challenge lies in the trust placed in tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must employ modern tools, methods, and processes to ensure every critical decision leaves a trace: who posted what, validated what, when, through which channel, and with what security guarantees?
More Stories
Senegal politics: imam kanté’s sharp response to moundiaye cissé on ousmane sonko
Imam Kanté weighs in on Moundiaye Cissé’s remarks about Ousmane Sonko
Health concerns and free speech debates around Paul Biya