Cameroon’s president: secure digital tools for remote leadership

The ability to review documents, exchange with advisors, and approve administrative actions remotely is now technically feasible. However, when it comes to the President of the Republic, remote work cannot rely on standard digital tools. It requires systems that guarantee information confidentiality, user authentication, document integrity, and traceability of every instruction.

This discussion gained momentum following a statement by Cameroon’s Minister of State for Higher Education, Professor Jacques Fame Ndongo. In a communiqué addressing concerns about a potential “vacancy” at the country’s highest leadership level, he emphasized that President Paul Biya continues to oversee state affairs and issue directives—either in person or through established electronic channels. Yet this raises a critical question: What secure digital tools should a modern presidential administration deploy when the head of state is outside national borders?

Posting a decree on social media represents merely the final step in public communication. It reveals nothing about the process behind its preparation, transmission, review, signing, recording, or archiving.

Institutional email addresses under @prc.cm

The foundational requirement is the systematic use of official email addresses linked to the Presidency’s domain. Advisors should have personalized institutional accounts—such as [email protected]—as well as functional addresses dedicated to the General Secretariat, Civil Cabinet, and other departments. Priority should be given to addresses like [email protected] for official correspondence.

Personal email accounts such as Gmail, Yahoo, or similar services must never be used for transmitting draft decrees, confidential memos, appointment files, diplomatic correspondence, or any state-sensitive instructions. The risks extend beyond technical security weaknesses: personal accounts fall outside state governance, making it difficult to control account creation, device access, message retention, retrieval, or deactivation upon a staff member’s departure.

A professional messaging system under @prc.cm would enable:

  • Controlled account management: creation and revocation of staff accounts
  • Enhanced authentication: mandatory multi-factor verification
  • Secure record-keeping: retention of official exchanges
  • Anomaly detection: identification of suspicious login attempts
  • Restricted forwarding: blocking automatic transfers to personal inboxes
  • Unified security policies: standardized encryption and archiving protocols

To prevent identity theft and phishing, the system should implement SPF, DKIM, and DMARC protocols. Communications between servers must also be encrypted. Even with a secure institutional address, sensitive documents should not be sent as email attachments. Instead, the system should notify the recipient that a file is available in a secure presidential platform.

A dedicated presidential document management platform

The Presidency needs an electronic document management system tailored to state affairs. Each file should be tracked with:

  • Unique identifiers for easy referencing
  • Author attribution for accountability
  • Confidentiality levels to control access
  • Authorized users with role-based permissions
  • Version control to track changes and approvals
  • Audit trails for every interaction
  • Timestamped validations to confirm approvals

With this platform, the President can access documents from a secure terminal, add comments, request revisions, or approve proposals—without files being copied across devices or shared via personal email.

For highly sensitive files, the system should prevent local downloads, printing, text copying, or unauthorized transfers. It should log every access attempt—identifying the user, time, device, and any modifications made.

Verifiable electronic signatures for presidential decrees

Remote approval of decrees or decisions must never rely on scanned images of a signature. Instead, a digital signature based on cryptographic certificates provides verification of:

  • Signatory identity: confirming the President’s authorization
  • Document integrity: ensuring the file has not been altered
  • Timestamp accuracy: recording exact approval time
  • Fraud prevention: detecting post-signature modifications

The cryptographic key used for critical acts must be stored in a hardware security module—not on a standard computer, USB drive, or personal device. Any use of this key should require direct presidential authentication and generate a time-stamped log entry.

For major decisions, the process should include multiple layers of verification: presidential approval, technical signature validation, legal review, official recording, and public release.

Zero Trust architecture for remote access

While a virtual private network (VPN) can secure connections between a traveling official and presidential servers, it should not be the sole safeguard. A Zero Trust model assumes no user, device, or network is inherently trustworthy. Access requests should be evaluated based on:

  • User identity and role permissions
  • Device recognition (institutional hardware only)
  • Location verification (trusted geographic zones)
  • Document sensitivity level
  • Behavioral analysis during the session

Accessing a presidential file could require simultaneous confirmation via an institutional computer, digital certificate, encrypted connection, physical security key, and local biometric verification on the device.

Exclusively institutional devices for state business

Presidential documents must never be accessed via personal phones or computers. Advisors in the Civil Cabinet, General Secretariat, and relevant departments should use equipment and mobile terminals owned by the institution and managed by a specialized IT team. These devices must be:

  • Fully encrypted to protect data at rest and in transit
  • Regularly updated to patch vulnerabilities
  • Restricted to authorized applications with no personal use
  • Geolocated and remotely wipeable in case of loss or theft
  • Auto-locking after brief inactivity
  • Prohibited from connecting to unsecured public Wi-Fi

A centralized endpoint management system would allow the administration to deploy updates, block high-risk apps, revoke devices, and remotely erase data if compromised.

Phishing-resistant authentication protocols

A complex password is not enough to secure access to presidential files. Authentication must combine:

  • Institutional device recognition
  • Personal PIN code
  • Physical security key (for high-level access)
  • Optional biometric verification (fingerprint or facial recognition)

While SMS-based codes add a layer of security, they remain vulnerable to certain attacks. For the most sensitive accounts, physical keys and digital certificates offer stronger resistance to phishing attempts. Staff should also receive regular training on identifying fraudulent messages, urgent scams, malicious links, and impersonation attempts targeting superiors.

WhatsApp for alerts, not for sensitive documents

WhatsApp is widely used in Cameroon, including within government circles, thanks to its end-to-end encryption. However, this does not make it a secure platform for transmitting presidential files. Risks include:

  • Device compromise (lost, stolen, or inspected phones)
  • Screen captures or unauthorized sharing
  • Backups on unsecured storage
  • Personal devices of former staff retaining access

WhatsApp lacks the mechanisms to classify files, manage permissions, preserve versions, validate actions, or archive documents. It should only be used for low-risk coordination—such as notifying that a file is available in the secure platform. For example: “The document referenced PRC/SG/2026/125 is ready for review in your secure workspace.” The file itself must never be attached.

The guiding principle: Use WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision-making, signing, and archiving.

Secure government videoconferencing solutions

Remote meetings between the President and advisors should rely on dedicated government-grade videoconferencing platforms. These systems must ensure:

  • End-to-end encryption of all communications
  • Strict participant authentication
  • Controlled invitations with no public links
  • No unauthorized recordings
  • Comprehensive access logs
  • Institutional device requirements
  • Sovereign data hosting within national infrastructure

Public links, free accounts, and unvetted applications must never be used for meetings involving defense, diplomacy, appointments, or government arbitrations.

Classifying documents by sensitivity levels

Not all presidential documents carry the same risk. A classification policy should define four tiers:

  • Public: intended for public dissemination
  • Internal: restricted to government services
  • Confidential: disclosure could harm public action
  • Highly sensitive: defense, intelligence, diplomacy, strategic appointments, or major arbitrations

Each level determines the authorized transmission channel, permitted users, device restrictions, printing permissions, retention periods, and archiving procedures. A public document may be sent via institutional email, but a highly sensitive file should only be accessible through a highly secured, compartmentalized platform.

Complete traceability of every decision

Every consultation, modification, validation, or transmission must be automatically logged. Security journals should capture:

  • Who accessed the document and their role
  • When the access occurred, including timestamps
  • Which device was used and its location
  • What changes were made and by whom
  • When the final version was approved
  • Who published the document and when

A dedicated security operations center could detect unusual activity—such as logins from unrecognized devices, bulk document downloads, or unauthorized modifications—and trigger alerts. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over the authenticity of a decision.

Distinguishing official decisions from social media posts

Presidential pages on Facebook and X are valuable for public communication—but they are not the systems used to prepare and validate decisions. Before a decree is published online, it must follow a secure process:

  • Transmission through an authorized channel
  • Authentication of the competent authority
  • Integrity verification of the final version
  • Timestamped validation to confirm approval
  • Preservation of the original in official archives

A scanned signature published online does not constitute digital proof. The security lies in the entire process that preceded the publication.

Ten priority measures for the Presidency

To modernize remote presidential work while maintaining the highest security standards, the administration should implement the following ten measures:

  1. Mandate the use of professional email under the @prc.cm domain for all state business.
  2. Prohibit personal Gmail, Yahoo, and similar accounts for official communications.
  3. Deploy a presidential electronic document management platform.
  4. Implement a secure institutional electronic signature system.
  5. Provide phones and computers exclusively for official use.
  6. Enforce phishing-resistant multi-factor authentication.
  7. Reserve WhatsApp for alerts and coordination—never for file sharing.
  8. Adopt a sensitivity-based document classification policy.
  9. Centralize access logs in a dedicated security monitoring center.
  10. Train staff regularly on espionage, phishing, and information leakage risks.

While there is no public evidence that all these measures are currently in place, they represent the minimum security standards required for an institution responsible for remotely processing documents that impact national finances, diplomacy, security, and governance continuity.

These imperatives—secure document transmission, electronic signatures, data sovereignty, and digital continuity—are at the core of E-Gov’A 2026, the E-Governance and Digital Innovation Summit, Expo & Awards, scheduled for October 14–16, 2026, at the Palais des Congrès in Yaoundé. The event, held under the patronage of the Ministry of Posts and Telecommunications, will explore the theme: “Artificial intelligence and e-governance: building effective public services in a cashless, paperless Africa.”

The real question is not whether a president can work from Geneva, Paris, New York, or any other location. The critical challenge lies in ensuring that the tools used authenticate decisions, protect state secrets, trace instructions, and prevent any unauthorized modification, diversion, or fabrication of official acts.

Modern tools and accountability

Remote presidential work is not an insurmountable technological challenge. The true obstacle is trust—in the tools and procedures employed. In an era marked by artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital practices. It must embrace modern tools to ensure that every major decision leaves a clear trace: who posted what, approved what, when, through which channel, and with what security guarantees?