July 30, 2026

The African Tribune

Bold, independent reporting on Africa's most important stories, in English, every day.

Secure digital tools for remote presidential work in Cameroon

Cameroon explores secure digital tools for presidential remote governance

President Paul Biya

Yaoundé – The ability to review documents, coordinate with teams, and approve administrative decisions remotely has become commonplace in modern governance. However, when the head of state is involved, this remote work cannot rely on conventional digital tools. It requires systems capable of guaranteeing information confidentiality, decision-maker authentication, document integrity, and traceability of every instruction.

The discussion around remote governance was reignited by a statement from Cameroon’s state minister of Higher Education, Professor Jacques Fame Ndongo. In a communiqué rejecting claims of a “vacancy” at the state’s helm, he asserted that President Paul Biya continues to oversee files and issue directives, “in person” or through “electronic means known to all.”

This declaration raises a critical question: what digital tools should a modern presidency adopt to receive, review, approve, and archive sensitive documents when the head of state is outside national territory?

Publishing a decree on social media or an official website represents only the final step in public communication. It reveals nothing about the process through which the document was prepared, transmitted, examined, signed, recorded, and preserved.

Institutional email addresses under the @prc.cm domain

The first requirement should be the systematic use of official email addresses linked to the Presidency’s domain. Presidential staff must have personalized accounts, such as [email protected], alongside functional addresses reserved for the General Secretariat, Civil Cabinet, and other departments. For instance, [email protected] should be prioritized for official communications.

Personal accounts like Gmail or Yahoo should never be used for state matters, including decree drafts, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The issue extends beyond the technical security capabilities of these platforms. It fundamentally lies in governance: a personal address is partially outside state control—its creation, connected devices, message retention, recovery, or deactivation after an official’s departure are not fully managed by the administration.

A professional messaging system under @prc.cm would enable:

  • Account management: creation and revocation of staff accounts;
  • Enhanced authentication: implementation of multi-factor authentication;
  • Traceability: preservation of official exchanges;
  • Security monitoring: detection of suspicious login attempts;
  • Data protection: prevention of automatic transfers to personal mailboxes;
  • Policy enforcement: uniform security and archiving standards.

Such a system must also defend against identity theft and phishing via protocols like SPF, DKIM, and DMARC, alongside encrypted server-to-server communications. Even with a secure institutional address, sensitive documents should not be sent as simple attachments. Instead, recipients should be notified that a file is available in a secure presidential platform.

A presidential platform for document management

The Presidency should deploy an electronic document management system tailored to state affairs. Each file could be logged with:

  • Unique reference: identification code for the document;
  • Author identity: clear attribution of the creator;
  • Confidentiality level: categorization of sensitivity;
  • Access permissions: authorized personnel designation;
  • Version control: tracking of document iterations;
  • Comments and approvals: record of feedback and decisions;
  • Validation timestamp: date and time of final approval;
  • Access history: comprehensive audit trail of all interactions.

This system would allow the president to consult documents from a secure terminal, add observations, request modifications, or approve proposals without files being copied across multiple devices or sent to personal mailboxes.

For highly sensitive documents, the platform should restrict local downloads, printing, text copying, or unauthorized transfers. It should also log who accessed a document, when, from which device, and what changes were made.

Verifiable electronic presidential signatures

Remote validation of decrees or decisions should not rely on scanned signature images. Instead, an electronic signature based on digital certificates would verify:

  • Signatory identity: confirmation of the president’s authorship;
  • Document integrity: assurance the file was not altered;
  • Timestamp: precise date and time of validation;
  • Tamper-proofing: detection of post-signature modifications.

The cryptographic key for signing critical documents must be stored in a highly secure hardware module—not on a standard computer, USB drive, or personal device. Its use should require direct presidential authentication and generate a timestamped log.

For major decisions, the process could involve multiple checks: presidential validation, technical signature verification, legal review of the act, official registration, and public release.

Zero Trust architecture for remote access

A virtual private network (VPN) secures connections between officials abroad and presidential servers, but it should not be the sole safeguard. The Presidency could adopt a Zero Trust framework, which assumes no user, device, or network is inherently trustworthy.

Every access request would be verified based on:

  • User identity: confirmation of the individual’s credentials;
  • Device integrity: scrutiny of the terminal’s security status;
  • Location verification: assessment of the connection’s origin;
  • Document sensitivity: alignment with the file’s confidentiality level;
  • Authorized permissions: scope of the user’s access rights;
  • Behavioral analysis: detection of unusual activity patterns.

Access to presidential files could require simultaneous authentication via an institutional computer, digital certificate, encrypted connection, physical security key, and local biometric verification on the device.

Exclusively institutional devices for presidential staff

Presidential documents must never be accessed from staff members’ personal phones. Civil Cabinet, General Secretariat, and relevant department personnel should use institution-owned, centrally managed devices. These terminals must be:

  • Fully encrypted: protection against unauthorized access;
  • Regularly updated: installation of security patches;
  • Application-restricted: installation of only approved software;
  • Separate from personal use: clear division between work and private activities;
  • Remotely wipeable: data erasure in case of loss or theft;
  • Auto-locking: automatic screen lock after inactivity;
  • Public Wi-Fi restricted: prohibition of connections to unsecured networks.

A centralized device management solution would enable the administration to deploy updates, block hazardous applications, revoke devices, and remotely delete data in case of compromise.

Phishing-resistant authentication protocols

A complex password alone is insufficient for accessing presidential files. Authentication should combine:

  • Institutional device recognition: verification of the terminal’s identity;
  • Personal code: entry of a secure PIN or passphrase;
  • Physical security key: hardware-based authentication;
  • Biometric verification (optional): local fingerprint or facial recognition.

While SMS codes enhance security, they remain vulnerable to certain attacks. For the most sensitive accounts, physical keys and digital certificates offer superior resistance to phishing attempts.

Staff should also undergo regular training to recognize fraudulent messages, urgent scams, malicious links, and attempts to impersonate superiors.

WhatsApp: useful for alerts, not document transmission

WhatsApp is widely used in Cameroon, including within administrations, thanks to its end-to-end encryption. However, this does not qualify it as an official platform for presidential document management.

A file shared via WhatsApp remains exposed to risks such as:

  • Device loss or espionage: unauthorized access to phones;
  • Screenshot capture: potential for data leaks;
  • Unauthorized transfers: sharing with unintended recipients;
  • Associated devices: vulnerabilities across linked accounts;
  • Inadequate backups: insufficiently protected cloud storage;
  • Departed staff: lingering access by former officials.

WhatsApp lacks the mechanisms to classify documents, manage permissions, track versions, record approvals, electronically sign acts, or ensure archival compliance. The app could instead be used to announce a file’s availability in a secure space, confirm meetings, or coordinate urgent actions.

For example, a collaborator might send: “Document PRC/SG/2026/125 is available in your secure workspace for review.” The file itself should never be attached to the conversation.

The guiding principle: WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision-making, signing, and archiving.

Secure government videoconferencing solutions

Remote exchanges between the president and collaborators could utilize a dedicated government videoconferencing platform with:

  • End-to-end encryption: protection of all communications;
  • Participant verification: authentication of each attendee;
  • Strict invitation control: prohibition of unauthorized access;
  • Unauthorized recording prevention: blocking unsanctioned captures;
  • Activity logging: retention of connection records;
  • Institutional device exclusivity: use of official terminals only;
  • Data sovereignty: control over data hosting and storage.

Public links, free accounts, and unvetted applications must never be used for meetings concerning defense, diplomacy, appointments, or government arbitrations.

Document classification by sensitivity level

Not all presidential documents carry the same risk. A classification policy could define four tiers:

  • Public: intended for public dissemination;
  • Internal: reserved for state services;
  • Confidential: disclosure could harm public action;
  • Highly sensitive: related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each level would dictate the authorized transmission channel, permitted personnel, device usage, printing permissions, retention duration, and archival methods. A public document might be sent via professional email, while a highly sensitive file should remain accessible only through a tightly secured platform.

Comprehensive traceability of every decision

Every consultation, modification, validation, or transmission should be automatically logged. The security journal must detail:

  • Who accessed the document: identification of the user;
  • When it was accessed: precise timestamp;
  • Device and location: origin of the request;
  • Modifications made: changes to the file;
  • Final validation: who approved the definitive version;
  • Publication records: when and by whom the document was published.

A dedicated security operations center could detect unusual connections, mass document downloads, access from unrecognized devices, or anomalous modifications to official acts. This traceability would also aid in reconstructing events during leaks, intrusions, or disputes over decision authenticity.

Distinguishing official decisions from social media posts

Presidential Facebook pages and X accounts enable rapid public dissemination, but they must not be conflated with the systems used to prepare and validate decisions. Before a decree is posted online, it must follow a secure process:

  • Document transmission: via an authorized channel;
  • Authority authentication: verification of the competent official;
  • Integrity assurance: confirmation the final version was unaltered;
  • Timestamped validation: precise recording of approval;
  • Official archiving: retention of the original in state records.

A visible signature on a published image does not constitute comprehensive digital proof. Security relies on the entire preceding process.

Ten priority measures for the Presidency

The Presidency could implement ten critical actions:

  1. Mandate professional email: enforce the use of @prc.cm addresses;
  2. Ban personal accounts: prohibit Gmail, Yahoo, and similar services for state matters;
  3. Deploy a document management platform: establish a secure presidential system;
  4. Introduce secure electronic signatures: implement digital certificate-based validation;
  5. Provide exclusively institutional devices: issue official phones and computers;
  6. Enforce multi-factor authentication: implement phishing-resistant protocols;
  7. Limit WhatsApp use: reserve the app for alerts and coordination;
  8. Classify documents: implement a tiered sensitivity policy;
  9. Centralize access logs: establish a security operations center;
  10. Conduct regular staff training: educate teams on espionage, phishing, and leaks.

While no public evidence confirms the full deployment of these measures by Cameroon’s Presidency, they represent the minimum safeguards required for an institution managing remote files critical to national finances, diplomacy, security, and continuity. The stakes—secure document transmission, electronic signatures, data sovereignty, and digital state continuity—will be central to E-Gov’A 2026, the E-Governance and Digital Innovation Summit & Expo, slated for October 14–16, 2026 in Yaoundé.

The event, themed “Artificial Intelligence and E-Governance: Building Efficient Public Services in a Cashless, Paperless Africa,” will convene public decision-makers, development agencies, government institutions, businesses, experts, and private sector stakeholders across Africa to explore digital transformation in governance.

The question is not whether a president can work from Geneva, Paris, New York, or elsewhere. The essence lies in whether the tools used authenticate decisions, protect state secrets, trace instructions, and prevent unauthorized modifications or fabrications in the president’s name.

Modern tools and unbroken traceability

Remote presidential work is not an insurmountable technological challenge. The real hurdle is the trust placed in tools and procedures. In an era marked by artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must harness modern solutions to ensure that every pivotal decision leaves an indelible record: who did what, when, through which channel, and with what security guarantees?