July 30, 2026

The African Tribune

Bold, independent reporting on Africa's most important stories, in English, every day.

Secure digital tools for remote presidential work in Cameroun

Secure digital tools for remote presidential work in Cameroon

Accessing sensitive files from abroad, coordinating with advisors, issuing orders, or approving administrative acts is now feasible with modern technology. However, when the president of the Republic needs to operate remotely, the system cannot rely on ordinary digital tools. Instead, it requires robust solutions that ensure:

  • Strict confidentiality of classified information
  • Verified identity of the decision-maker
  • Document integrity at every stage
  • Full traceability of each instruction

The recent remarks by Cameroon’s Minister of State for Higher Education, Professor Jacques Fame Ndongo, reignited discussions about the president’s remote governance. He confirmed that President Paul Biya continues to oversee national affairs, whether in person or through established electronic channels. Yet, this raises a critical question: What secure digital infrastructure should a modern presidential office deploy to receive, review, approve, and archive sensitive documents when the head of state is abroad?

Publication on social media or official websites is merely the final step in communication. It reveals nothing about the internal process — how a document was drafted, transmitted, reviewed, signed, recorded, or preserved.

Mandatory institutional email under the @prc.cm domain

The foundation of secure remote governance begins with official email addresses linked to the Presidency’s domain. Every advisor should have a personal institutional account — such as [email protected] — alongside functional addresses for the General Secretariat, Civil Cabinet, and other key departments. For example, [email protected] should be the primary channel for all official correspondence.

Using personal accounts like Gmail or Yahoo for state affairs introduces significant risks. Beyond technical vulnerabilities, these accounts fall outside state control. Authorities cannot guarantee:

  • Secure creation and deactivation of accounts
  • Protection against unauthorized access or data leaks
  • Maintenance of message archives after staff departures
  • Prevention of automatic forwarding to private inboxes

A dedicated presidential messaging system would enable:

  • Centralized account management and revocation
  • Enforced multi-factor authentication
  • Secure retention of official exchanges
  • Real-time detection of suspicious login attempts
  • Strict adherence to government-wide security and archiving policies

To prevent identity theft and phishing, the system must implement SPF, DKIM, and DMARC protocols and enforce end-to-end encryption for all server communications.

Even with a secure institutional address, sensitive documents should never be sent as email attachments. Instead, the system could notify recipients that a file is ready for review in a secure presidential platform.

A dedicated presidential document management platform

A specialized electronic document management system (EDMS) is essential for handling state affairs remotely. Each file should be logged with:

  • A unique identifier
  • The author’s identity
  • A confidentiality classification level
  • List of authorized viewers
  • Full version history
  • Comments and approvals
  • Validation timestamp
  • Complete access audit trail

With this platform, the president can:

  • View documents from a secure terminal
  • Add observations or request revisions
  • Authorize or reject proposals
  • Approve decisions without copying files to personal devices

For highly classified documents, the system can restrict actions such as downloading, printing, copying text, or sharing with unauthorized parties. It also tracks who accessed the file, when, from which device, and what changes were made.

Digitally signed presidential orders with full verification

Remote approval of decrees or decisions must go beyond scanned signatures. A secure electronic signature, based on digital certificates, ensures:

  • Verification of the signatory’s identity
  • Assurance that the document has not been altered
  • Timestamp of validation
  • Immutability after signing

Cryptographic keys used for critical acts must be stored in hardware security modules (HSMs) — not on personal computers, USB drives, or phones. Each use of the key should require direct authentication by the president and generate a time-stamped audit log.

For major decisions, the process can include multiple layers: presidential approval, technical signature verification, legal review, official registration, and public release.

Zero Trust architecture for secure remote access

A traditional VPN can secure connections between officials and presidential servers, but it is not enough. A Zero Trust model assumes no user, device, or network is inherently trustworthy. Every access request is evaluated based on:

  • User identity
  • Device authenticity
  • Geolocation of the connection
  • Document sensitivity level
  • Assigned user permissions
  • Behavioral patterns during the session

Accessing a presidential file could require:

  • An authorized institutional device
  • A digital certificate
  • Encrypted connection
  • A physical security key
  • A local biometric scan

Exclusively institutional devices for sensitive tasks

Presidential documents must never be accessed from personal phones or computers of advisors. Staff in the Civil Cabinet, General Secretariat, and related departments should use institutionally owned and managed devices that are:

  • Fully encrypted
  • Regularly updated with security patches
  • Restricted to approved applications only
  • Segregated from personal use
  • Remotely wipeable in case of loss
  • Auto-locked after short inactivity
  • Blocked from connecting to unsecured public Wi-Fi

A centralized mobile device management (MDM) system would allow administrators to push updates, block risky apps, revoke devices, and remotely erase data if compromised.

Anti-phishing authentication protocols

A complex password alone is insufficient for accessing presidential systems. Authentication should combine:

  • An approved institutional device
  • A personal PIN
  • A physical security key
  • Optional local biometric verification

While SMS-based one-time codes add security, they remain vulnerable to interception. For high-risk accounts, hardware keys and digital certificates offer stronger resistance to phishing attacks.

Staff training is also vital. Regular awareness programs should teach employees how to spot fake messages, fraudulent urgent requests, malicious links, and attempts to impersonate superiors.

WhatsApp: ideal for alerts, not for file sharing

WhatsApp is widely used in Cameroon, including in government circles, thanks to its end-to-end encryption. However, this does not qualify it as an official platform for transmitting presidential documents.

Files shared via WhatsApp remain exposed through:

  • Lost or compromised phones
  • Screenshots
  • Unauthorized forwarding
  • Linked personal devices
  • Inadequately protected backups
  • Devices of former employees

WhatsApp lacks the features required for document classification, access control, versioning, electronic signing, or official archiving. It can, however, be used to alert teams:

« The document referenced PRC/SG/2026/125 is now available in your secure workspace for review. »

The actual file should never be attached to the message.

In short: Use WhatsApp to coordinate and signal urgency; use the secure presidential platform to transmit, review, decide, sign, and archive.

Secure government video conferencing

Remote meetings between the president and advisors should use a dedicated, government-grade video conferencing solution that provides:

  • End-to-end encryption
  • Participant identity verification
  • Strict invitation control
  • Prohibition of unauthorized recordings
  • Centralized logging of all connections
  • Use of only institutional devices
  • Full data hosting control

Public links, free accounts, and unvetted apps must never be used for sensitive discussions involving defense, diplomacy, appointments, or government arbitration.

Document classification by sensitivity level

Not all presidential documents carry the same risk. A classification policy could define four tiers:

  • Public: intended for public release
  • Internal: working documents for government services only
  • Confidential: disclosure could harm public action
  • Highly sensitive: related to defense, intelligence, diplomacy, key appointments, or major decisions

Each level dictates:

  • Allowed transmission channels
  • Authorized personnel
  • Permitted devices
  • Printing restrictions
  • Retention duration
  • Archiving procedures

A public document may be sent via professional email, but a highly sensitive file must remain accessible only through a tightly controlled platform.

Full traceability of every decision

Every consultation, modification, approval, or transmission must be automatically logged. The security journal should record:

  • Who accessed the document
  • When it was accessed
  • From which device
  • What changes were made
  • Who validated the final version
  • When it was officially recorded and published

A dedicated security operations center could detect unusual activity — such as logins from unknown devices, mass downloads, or unauthorized modifications — and respond swiftly. This traceability also enables reconstruction of events in case of leaks, intrusions, or disputes over authenticity.

Distinguishing official decisions from social media posts

Presidential Facebook pages and X accounts are effective for public communication, but they must not be confused with the systems used to prepare and approve decisions.

Before a decree is published online, it must pass through a secure process ensuring:

  • Transmission via authorized channels
  • Authentication of the competent authority
  • Integrity of the final version
  • Timestamped validation
  • Preservation of the original in official archives

A visible signature on a published image does not constitute full digital proof. The security lies in the entire process leading up to publication.

Ten priority measures for the Presidency

To establish a secure remote governance framework, the Presidency should implement the following ten actions:

  1. Make institutional email under @prc.cm mandatory
  2. Ban personal accounts like Gmail or Yahoo for official business
  3. Deploy a presidential electronic document management platform
  4. Introduce secure institutional electronic signatures
  5. Provide exclusively institutional phones and computers
  6. Enforce multi-factor authentication resistant to phishing
  7. Restrict WhatsApp to alerts and coordination
  8. Classify documents by sensitivity level
  9. Centralize access logs in a security operations center
  10. Train staff regularly on espionage, phishing, and data leakage risks

While no public evidence confirms that all these measures are currently in use, they represent the minimum standards a modern presidential institution should adopt when handling remote governance of national finances, diplomacy, security, and continuity.

These challenges — secure document transmission, electronic signatures, data sovereignty, and digital state continuity — will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, to be held from October 14 to 16, 2026, at the Palais des Congrès in Yaoundé. The event, organized under the high patronage of the Ministry of Posts and Telecommunications, will explore the theme: « Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa ».

The real challenge: trust in tools and procedures

Remote presidential work is not a technological hurdle — it is a matter of trust. In an era marked by artificial intelligence, cyberattacks, and digital forgeries, the state cannot rely on informal digital methods. It must adopt modern tools and procedures that ensure every critical decision leaves a verifiable trace: who posted what, approved what, when, through which channel, and with what security guarantees?