The ability to manage state affairs from abroad—reviewing files, issuing directives, or approving administrative acts—is now technically feasible. Yet when the task involves the Head of State, remote governance cannot rely on ordinary digital tools. It demands systems capable of ensuring information confidentiality, verifying the decision-maker’s identity, maintaining document integrity, and tracking every instruction.

This critical question resurfaced following a statement by Cameroon’s Minister of Higher Education, Jacques Fame Ndongo. In a public communiqué rejecting claims of a “vacancy” at the state’s highest level, he confirmed that President Paul Biya continues to oversee national matters—whether in person or through “electronic means known to all.”

Beyond the political implications, this raises a fundamental issue: what secure digital infrastructure should a modern presidency deploy to receive, process, approve, and archive sensitive documents when the Head of State is abroad?

Posting a decree on social media represents only the final step in public communication. It reveals nothing about the secure workflow that prepared, transmitted, reviewed, signed, recorded, and preserved the document.

institutional email under @prc.cm

Priority must be given to official email addresses linked to the Presidency’s domain. Collaborators should use institutional accounts such as [email protected], alongside functional addresses for the General Secretariat, Civil Cabinet, and other departments—like [email protected].

Personal accounts (Gmail, Yahoo, etc.) must never be used for state business involving draft decrees, confidential memos, diplomatic correspondence, or binding instructions. Beyond technical security limitations, these private accounts fall outside state oversight: their creation, device access, message retention, and deactivation upon staff departure remain beyond administrative control.

A professional messaging system under @prc.cm would enable:

  • creation and revocation of staff accounts;
  • mandatory multi-factor authentication;
  • secure retention of official exchanges;
  • detection of suspicious logins;
  • blocking automatic forwarding to personal inboxes;
  • consistent security policies and archiving protocols.

Protection against identity theft and phishing requires SPF, DKIM, and DMARC protocols, alongside encrypted server-to-server communication. Even with a secured institutional address, highly sensitive documents should not be sent as attachments. Instead, the system should notify recipients that a file is available in a secure presidential portal.

a presidential document management platform

The Presidency requires a dedicated electronic document management system for state affairs. Each file should be registered with:

  • a unique reference;
  • the author’s identity;
  • confidentiality classification;
  • authorized viewer lists;
  • version history;
  • comments and approvals;
  • validation timestamps;
  • a complete access audit trail.

This allows the Head of State to review documents from a secure terminal, add observations, request revisions, or grant approvals—without files being copied across devices or sent to personal mailboxes. For the most sensitive dossiers, the platform should block local downloads, printing, text copying, or unauthorized sharing. Every access, modification, and validation should be logged, including timestamps, device details, and user identities.

verifiable electronic signatures for presidential acts

Remote validation of decrees or decisions must not rely on scanned images of a signature. Instead, a cryptographic signature—based on digital certificates—should confirm:

  • the signatory’s identity;
  • document integrity;
  • exact time of validation;
  • absence of post-signature alterations.

The cryptographic key for high-level acts must be stored in a tamper-proof hardware module—not on ordinary computers, USB drives, or personal phones. Every use should require direct presidential authentication and generate a time-stamped audit trail. For critical decisions, the process could include multiple checks: presidential approval, technical signature verification, legal review, official registration, and public release.

zero trust architecture for remote access

A virtual private network (VPN) secures remote connections—but it cannot be the sole safeguard. The Presidency should adopt a Zero Trust model: no user, device, or network should be trusted by default. Access requests must be evaluated based on:

  • user identity;
  • device legitimacy;
  • connection location;
  • document sensitivity level;
  • assigned user privileges;
  • behavioral patterns during the session.

Accessing a presidential file might require an institutional device, digital certificate, encrypted connection, physical security key, and local biometric verification—all simultaneously.

exclusively institutional devices for state officials

State business must never be conducted on personal phones or computers. Civil Cabinet members, General Secretariat staff, and other officials handling presidential documents should use institutionally issued and centrally managed devices. These must be:

  • fully encrypted;
  • regularly updated;
  • restricted to approved applications;
  • isolated from personal use;
  • remotely wipeable if lost;
  • automatically locked after inactivity;
  • blocked from unsecured public Wi-Fi networks.

A centralized terminal management system would allow administrators to push updates, block malicious apps, revoke devices, and remotely erase data in case of theft or compromise.

anti-phishing authentication protocols

A strong password alone is insufficient for accessing presidential systems. Authentication should combine:

  • an institutional device;
  • a personal PIN;
  • a physical security key;
  • optional local biometric verification.

SMS codes can enhance security but remain vulnerable to interception. For high-risk accounts, physical keys and digital certificates offer superior resistance to phishing. Staff should also undergo regular training to recognize fraudulent messages, urgent scams, malicious links, and impersonation attempts.

whatsapp for alerts only—not document transmission

While widely used in Cameroon—including within administrations—WhatsApp’s end-to-end encryption protects message content in transit. However, it cannot serve as an official document management platform. Sensitive files shared via WhatsApp remain exposed through:

  • lost or compromised phones;
  • screenshot captures;
  • unauthorized forwarding;
  • linked devices under the same account;
  • insufficiently secured backups;
  • personal phones of former staff.

WhatsApp also lacks mechanisms for document classification, access control, versioning, electronic signing, or archival compliance. Instead, it can be used to alert recipients that a dossier is available in the secure presidential portal—for example: “The file PRC/SG/2026/125 is ready for review in your secure workspace.”

The guiding principle: “Use WhatsApp to coordinate and alert; rely on the secure presidential platform to transmit, review, decide, sign, and archive.”

government-grade secure videoconferencing

Remote exchanges between the President and collaborators should occur via a dedicated government videoconferencing solution offering:

  • encrypted communications;
  • verified participant identities;
  • strict invitation controls;
  • prohibition of unauthorized recordings;
  • connection logging;
  • exclusive use of institutional devices;
  • data hosting under national control.

Public links, free accounts, and unvetted apps must never be used for meetings involving defense, diplomacy, nominations, or government arbitration.

document classification by sensitivity level

Not all presidential documents carry equal risk. A classification policy could define four tiers:

  • Public: intended for public dissemination;
  • Internal: restricted to government services;
  • Confidential: disclosure could harm public action;
  • Highly Sensitive: covering defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each tier determines the authorized transmission channel, permitted users, acceptable devices, printing permissions, retention periods, and archival procedures. A public document might be sent via professional email, while a highly sensitive file should only be accessible within a tightly controlled portal.

comprehensive traceability for every decision

Every consultation, modification, validation, or transmission must be automatically recorded. The security log should specify:

  • who accessed the document;
  • when the access occurred;
  • which device was used;
  • what changes were made;
  • who approved the final version;
  • when the document was officially recorded and published.

A dedicated security operations center could flag unusual logins, bulk downloads, access from unrecognized devices, or unauthorized modifications to official acts. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over decision authenticity.

distinguishing official decisions from social media posts

The Presidency’s Facebook and X accounts inform the public rapidly—but they are not the systems used to prepare and validate decisions. Before a decree appears online, it must follow a secure workflow:

  • transmitted via an authorized channel;
  • authenticated by the competent authority;
  • verified as the definitive version;
  • time-stamped upon validation;
  • preserved in official archives.

A visible signature on a published image does not constitute full digital proof. Security lies in the complete, traceable process behind the publication.

ten priority measures for the presidency

The Presidency could implement ten immediate actions:

  1. Mandate professional email under @prc.cm;
  2. Ban personal accounts (Gmail, Yahoo, etc.) for state business;
  3. Deploy a presidential electronic document management platform;
  4. Introduce a secure institutional electronic signature system;
  5. Issue exclusively institutional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Restrict WhatsApp to alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security operations center;
  10. Train staff regularly on espionage, phishing, and information leaks.

While no public evidence confirms Cameroon’s Presidency currently employs all these measures, they represent the minimum safeguards required for an institution handling finance, diplomacy, security, and state continuity remotely. The challenges of secure document transmission, electronic signatures, data sovereignty, and digital continuity will be central to E-Gov’A 2026—E-Gov Africa Summit, Expo & Awards, taking place October 14–16, 2026, at the Yaoundé Congress Palace. The event, under the high patronage of the Ministry of Posts and Telecommunications, will explore the theme: “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa.”

The core question is not whether a president can work from Geneva, Paris, or New York—but whether the tools used can authenticate decisions, protect state secrets, trace instructions, and prevent anyone from altering, diverting, or fabricating an act in the president’s name.

Modern tools and robust traceability are within reach. The real challenge lies in trusting these systems and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must adopt advanced tools, means, and processes so that every critical decision leaves an immutable trail: who posted what, approved what, when, via which channel, and with what security guarantees?