The ability to review files, exchange with teams, issue directives, or approve administrative acts remotely is now technically feasible. Yet when it comes to the Head of State of Cameroon, distance work cannot rely on conventional digital tools. It requires systems capable of ensuring information confidentiality, verifying the decision-maker’s identity, maintaining document integrity, and tracking every instruction.
The debate on remote governance resurfaced following a statement by the Minister of Higher Education, Professor Jacques Fame Ndongo. In a communiqué denying any “vacancy” at the helm of the State, he asserted that President Paul Biya continues to oversee files and issue directives—either in person or through “electronic means known to all.” This claim raises a critical question: what secure digital tools should a modern Presidency deploy to receive, review, approve, and archive sensitive documents when the Head of State is abroad?
Posting a decree on Facebook, X, or the official Presidency website is merely the final step in public communication. It reveals nothing about how the document was drafted, transmitted, examined, signed, recorded, or preserved.
Institutional email under the @prc.cm domain
The first requirement is the systematic use of official email addresses tied to the Presidency’s domain. Staff must have personalized accounts—such as [email protected]—as well as functional addresses for the General Secretariat, Civil Cabinet, and other departments. Addresses like [email protected] should take priority. Personal accounts (Gmail, Yahoo, etc.) must never be used for transmitting draft decrees, confidential memos, appointment files, diplomatic correspondence, or state directives.
The issue isn’t just about the security features of consumer email services. It’s about governance: personal accounts fall partially outside state control. Authorities cannot always manage their creation, linked devices, message storage, recovery, or deactivation after a staff member leaves. A professional messaging system under @prc.cm would enable:
- Creating and revoking staff accounts;
- Enforcing strong authentication;
- Preserving official exchanges;
- Detecting suspicious logins;
- Blocking automatic forwarding to personal inboxes;
- Applying unified security and archiving policies.
This system must guard against identity theft and phishing via SPF, DKIM, and DMARC protocols, and encrypt server-to-server communications. Even a well-protected institutional address shouldn’t be used to send highly sensitive documents as attachments. Instead, it should notify recipients that a file is available in a secure presidential platform.
A presidential platform for document management
The Presidency needs an electronic document management system tailored to state affairs. Each file should be logged with:
- A unique reference;
- The author’s identity;
- Its confidentiality level;
- Authorized viewers;
- Document versions;
- Comments and approvals;
- Validation date;
- A full access history.
This allows the Head of State to consult a document from a secure terminal, add notes, request changes, or approve proposals without files being copied across devices or sent to personal mailboxes. For highly sensitive files, the platform must prevent local downloads, printing, text copying, or unauthorized transfers. It should also log who accessed the document, when, from which device, and what modifications were made.
A verifiable electronic presidential signature
Remote validation of decrees or decisions shouldn’t rely on a scanned image of the President’s signature. An electronic signature based on digital certificates ensures:
- The signatory’s identity;
- Document integrity;
- Validation date and time;
- No post-signature alterations.
The cryptographic key for signing critical acts must be stored in a highly secure hardware module—not on a regular computer, USB drive, or personal phone. Its use should require direct authentication by the Head of State and generate a time-stamped log. For major decisions, the process could include multiple checks: presidential validation, technical signature verification, legal review, official recording, and publication.
Zero Trust principles for remote access
A Virtual Private Network (VPN) secures connections between officials abroad and presidential servers—but it shouldn’t be the sole safeguard. The Presidency could adopt a Zero Trust architecture, assuming no user, device, or network is inherently trustworthy. Access requests should be verified based on:
- User identity;
- Device used;
- Connection location;
- Document sensitivity level;
- Assigned user rights;
- Behavioral patterns during the session.
Accessing a presidential file could require an institutional computer, digital certificate, encrypted connection, physical security key, and local biometric verification on the device.
Exclusively institutional phones and computers
Presidential files must never be accessed from staff members’ personal devices. Civil Cabinet, General Secretariat, and relevant department employees should use institution-owned, centrally managed equipment. These devices must be:
- Fully encrypted;
- Regularly updated;
- Restricted to approved applications;
- Segregated from personal use;
- Remotely wipeable if lost;
- Auto-locked after inactivity;
- Blocked from unsecured public Wi-Fi.
A centralized terminal management solution would allow authorities to push updates, block dangerous apps, revoke devices, and remotely delete data in case of theft or compromise.
Phishing-resistant authentication
A password—even a complex one—should never suffice for accessing Presidency files. Authentication must combine:
- An institutional device;
- A personal code;
- A physical security key;
- Optionally, local biometric verification.
SMS codes can enhance security but remain vulnerable to certain attacks. For the most sensitive accounts, physical keys and digital certificates offer stronger phishing resistance. Staff should also be regularly trained to recognize fake messages, fraudulent urgent requests, malicious links, and attempts to impersonate superiors.
WhatsApp: useful for alerts, not for transmitting files
WhatsApp is widely used in Cameroon, including in government circles, thanks to its end-to-end encryption. However, this doesn’t make it an official platform for managing presidential documents. A file sent via WhatsApp remains at risk:
- On a lost or compromised phone;
- Through screenshots;
- After unauthorized transfers;
- Across linked devices;
- In inadequately protected backups;
- On a departing employee’s personal phone.
WhatsApp also lacks mechanisms for document classification, access management, version control, electronic signing, or administrative archiving. It could, however, be used to announce that a file is available in a secure space—e.g., “The document referenced PRC/SG/2026/125 is ready for review in your secure workspace.” The file itself must never be attached.
The rule is clear: Use WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision-making, signing, and archiving.
Secure government videoconferencing
Remote exchanges between the President and collaborators could also rely on a dedicated government videoconferencing solution offering:
- Encrypted communications;
- Participant identification;
- Strict invitation control;
- Prohibition of unauthorized recordings;
- Connection log retention;
- Use of institutional terminals only;
- Data hosting oversight.
Public links, free accounts, and unvetted apps must never be used for meetings on defense, diplomacy, appointments, or government arbitrations.
Classifying documents by sensitivity
Not all Presidency documents carry the same risk. A classification policy could define four levels:
- Public: intended for dissemination;
- Internal: working documents for state services;
- Confidential: disclosure could harm public action;
- Highly sensitive: covering defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level dictates the allowed transmission channel, authorized personnel, permitted devices, printing options, retention duration, and archiving methods. A public document could be sent via professional email, while a highly sensitive file must remain accessible only through a tightly controlled platform.
Comprehensive traceability for every decision
Every consultation, modification, validation, or transmission must be automatically logged. The security journal should detail:
- Who accessed the document;
- When and from which device;
- What changes were made;
- Who approved the final version;
- When and by whom it was recorded and published.
A security operations center could detect unusual logins, mass document downloads, access from unrecognized devices, or unauthorized modifications to official acts. This traceability also helps reconstruct events in case of leaks, intrusions, or disputes over decision authenticity.
Avoid confusing official decisions with social media posts
Presidency Facebook pages and X accounts enable rapid public communication—but they aren’t the systems used to prepare and validate decisions. Before a decree is posted online, it must have followed an authorized process:
- The document was transmitted through an approved channel;
- The competent authority was authenticated;
- The final version was unaltered;
- Validation was time-stamped;
- The original is preserved in official archives.
A signature visible on an online image is not, in itself, full digital proof. Security lies in the entire process preceding publication.
Ten priority measures for the Presidency
To modernize remote governance, the Presidency could implement ten key actions:
- Mandate professional email under the @prc.cm domain;
- Ban personal Gmail, Yahoo, and similar accounts for state business;
- Deploy a presidential electronic document management platform;
- Introduce a secure institutional electronic signature;
- Provide exclusively professional phones and computers;
- Enforce multi-factor authentication resistant to phishing;
- Reserve WhatsApp for alerts and coordination;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Train staff regularly on espionage, phishing, and information leaks risks.
While no public evidence confirms that Cameroon’s Presidency currently uses all these measures, they represent the minimum safeguards a modern institution must adopt to handle remotely sensitive files involving finances, diplomacy, security, and state continuity. These challenges—secure document transmission, electronic signatures, data sovereignty, and digital continuity—will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, set for October 14–16, 2026, in Yaoundé. The event, held under the high patronage of the Ministry of Posts and Telecommunications, will explore the theme: “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa.”
The core question isn’t whether a president can work from Geneva, Paris, or New York. It’s whether the tools used authenticate their decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in their name.
Modern tools and accountability
Remote presidential work isn’t a technological hurdle. The real challenge is trust in tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the State can no longer rely on informal digital methods. It must deploy modern solutions to ensure every critical decision leaves a trace: who posted what, validated what, when, through which channel, and with what security guarantees?