The ability to review files, exchange with collaborators, issue directives or approve administrative acts remotely is now within reach. Yet when it comes to the President of the Republic, distance work cannot rely on ordinary digital tools. It demands systems capable of guaranteeing the confidentiality of information, the identity of the decision-maker, the integrity of documents and the traceability of every instruction.
The debate on remote governance was reignited following a statement by the Minister of State for Higher Education, Professor Jacques Fame Ndongo. In a communiqué denying claims of a “vacancy” at the helm of the state, he affirmed that President Paul Biya continues to oversee files and issue directives, “in person” or through “electronic means known to all.”
His remarks raise a broader question: what digital tools should a modern presidency use to receive, review, approve and archive sensitive documents when the head of state is outside national territory?
Publishing a decree on Facebook, X or the official presidency website represents only the final step in public communication. It reveals nothing about how the document was prepared, transmitted, examined, signed, registered or stored.
Professional email under the @prc.cm domain
The first requirement is the systematic use of institutional email addresses tied to the official presidency domain.
Staff working with the head of state must have personalised addresses such as [email protected], as well as functional addresses reserved for the General Secretariat, the Civil Cabinet and other departments. For instance, [email protected] should be prioritised.
Personal accounts from providers like Gmail or Yahoo must never be used to transmit draft decrees, confidential notes, appointment files, diplomatic correspondence or instructions of state significance.
The issue is not merely about the technical security capabilities of these platforms. It is about governance: a personal address lies partially outside state control. The administration does not always oversee its creation, the devices connected to it, message retention, retrieval or deactivation after a staff member departs.
A professional messaging system under @prc.cm would enable:
- creation and revocation of staff accounts;
- mandatory strong authentication;
- retention of official exchanges;
- detection of suspicious connections;
- blocking automatic transfers to personal inboxes;
- implementation of unified security and archiving policies.
This system must be shielded against identity theft and phishing through mechanisms like SPF, DKIM and DMARC, and must enforce encryption for server-to-server communications.
Even a well-protected institutional address should not be used to send highly sensitive documents as simple attachments. Instead, it could notify the recipient that a file is available in a secure presidential platform.
A presidential platform for document management
The presidency should operate an electronic document management system tailored to state affairs.
Each file could be logged with:
- a unique reference;
- the author’s identity;
- its confidentiality level;
- authorised users;
- all document versions;
- comments and approvals;
- the date of validation;
- a complete access history.
The head of state could then consult a document from a secure terminal, add observations, request changes or approve a proposal without the file being copied across multiple devices or sent to personal mailboxes.
For the most sensitive files, the platform should prevent local downloads, printing, text copying or transfers to unauthorised individuals. It should also allow tracking of who accessed the document, when, from which device and what modifications were made.
A verifiable electronic presidential signature
Remote validation of a decree or decision must not rely on a simple scanned image of the president’s signature.
An electronic signature based on digital certificates would confirm:
- the signatory’s identity;
- the document’s integrity;
- the date and time of validation;
- that no changes were made after signing.
The cryptographic key used for the most critical acts must be stored in a highly secure hardware module, never on an ordinary computer, USB drive or personal phone. Any use of this key should require direct authentication by the head of state and generate a time-stamped log.
For major decisions, the process could include multiple checks: presidential approval, technical signature verification, legal review of the act, official registration and then publication.
Zero Trust for remote access
A virtual private network can secure the connection between a travelling official and presidential servers, but it should not be the sole safeguard.
The presidency could adopt a Zero Trust architecture, which assumes that no user, device or network is inherently trustworthy. Every access request would be verified based on:
- user identity;
- device in use;
- location of connection;
- document sensitivity level;
- user permissions;
- observed behaviour during the session.
Access to a presidential file could thus require, simultaneously, an institutional computer, a digital certificate, encrypted connection, physical security key and biometric verification on the local device.
Exclusively institutional phones and computers
Presidential files must never be accessed from staff members’ personal phones.
Civil Cabinet, General Secretariat and relevant department staff should be equipped with devices owned and managed by the institution through a dedicated team.
These devices must be:
- fully encrypted;
- regularly updated;
- limited to approved applications;
- segregated from personal use;
- remotely wipeable in case of loss;
- automatically locked after a short idle period;
- prohibited from connecting to unsecured public Wi-Fi networks.
A centralised device management solution would allow the administration to install updates, block dangerous applications, revoke devices and remotely delete data in the event of theft or compromise.
Phishing-resistant authentication
A password, no matter how complex, should never suffice to access presidency files.
Authentication should combine:
- an institutional device;
- a personal code;
- a physical security key;
- possibly local biometric verification.
SMS codes can enhance security but remain vulnerable to certain attacks. For the most sensitive accounts, physical keys and digital certificates offer stronger protection against phishing.
Staff should also receive regular training to recognise fake messages, fraudulent urgent requests, malicious links and attempts to impersonate superiors.
WhatsApp: useful for alerts, not for transmitting files
WhatsApp is widely used in Cameroon, including within administrations, and its end-to-end encryption protects message content during transmission.
This protection does not, however, make it an official platform for managing presidential documents. A file sent via WhatsApp could still be exposed through:
- a lost or compromised phone;
- a screenshot;
- unauthorised forwarding;
- linked devices associated with the account;
- insufficiently protected backups;
- personal phones of former staff members.
WhatsApp also lacks the mechanisms to classify files, manage permissions, track versions, record validations, electronically sign acts or ensure administrative archiving.
The app could instead be used to announce that a file is available, confirm a meeting, signal an urgency or coordinate travel.
For instance, a staff member might send the message: “The file referenced PRC/SG/2026/125 is available in your secure workspace for review.”
The document itself should never be attached to the conversation.
The rule is simple: WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision, signing and archiving.
Secure government videoconferencing solutions
Remote exchanges between the president and collaborators could also use a dedicated government videoconferencing platform.
This solution should enable:
- encrypted communications;
- identity verification of each participant;
- strict control of invitations;
- prohibition of unauthorised recordings;
- retention of connection logs;
- exclusive use of institutional devices;
- data hosting oversight.
Public links, free accounts and unvetted applications must not be used for meetings concerning defence, diplomacy, appointments or government arbitrations.
Classifying documents by sensitivity
Not all presidential documents carry the same level of risk. A classification policy could define four categories:
- Public: documents intended for dissemination;
- Internal: working documents reserved for state services;
- Confidential: documents whose disclosure could harm public action;
- Highly sensitive: documents related to defence, intelligence, diplomacy, strategic appointments or major arbitrations.
Each level would determine the authorised transmission channel, permitted users, usable devices, printing permissions, retention periods and archiving procedures. A public document could be sent via professional email, whereas a highly sensitive file should remain accessible only through a tightly compartmentalised platform.
Comprehensive traceability of every decision
Every consultation, modification, validation or transmission must be automatically logged.
The security log should detail:
- who accessed the document;
- when they did so;
- from which device;
- what changes were made;
- who approved the final version;
- when the document was recorded and published, and by whom.
A security operations centre could detect unusual connections, mass downloads, attempts to access from unrecognised equipment or unauthorised modifications to an official act. This traceability would also help reconstruct events in the event of a leak, intrusion or dispute over the authenticity of a decision.
Distinguishing official decisions from social media posts
The presidency’s Facebook pages and X accounts allow rapid public communication but must not be confused with the systems used to prepare and validate decisions.
Before a decree is published on social media, it must follow a process:
- transmission through an authorised channel;
- authentication of the competent authority;
- verification that the final version has not been altered;
- time-stamped validation;
- preservation of the original in official archives.
Thus, a visible signature on an online image does not, on its own, constitute full digital proof. Security rests on the complete process preceding publication.
Ten priority measures for the presidency
The presidency could implement ten key actions:
- Mandate professional email under the @prc.cm domain;
- Prohibit personal Gmail, Yahoo and similar accounts for state business;
- Deploy a presidential electronic document management platform;
- Introduce a secure institutional electronic signature;
- Provide exclusively professional phones and computers;
- Enforce multi-factor authentication resistant to phishing;
- Limit WhatsApp to alerts and coordination;
- Classify documents by sensitivity level;
- Centralise access logs in a security operations centre;
- Train staff regularly on espionage, phishing and information leakage risks.
While no public evidence confirms that all these measures are currently in use by the Cameroonian presidency, they represent the minimum safeguards a body handling remotely sensitive state affairs—finance, diplomacy, security and continuity—should adopt.
Issues of secure document transmission, electronic signatures, data sovereignty and digital continuity will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, taking place from 14 to 16 October 2026 at the Palais des Congrès in Yaoundé. The event, organised under the high patronage of the Ministry of Posts and Telecommunications and themed “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa,” will bring together public decision-makers, development agencies, institutions, businesses and African experts.
The question is not merely whether a president can work from Geneva, Paris, New York or elsewhere. The essential challenge is whether the tools used can authenticate decisions, protect state secrets, trace instructions and ensure that no one can alter, divert or fabricate an act in the president’s name.
Modern tools and traceability
Remote presidential work is not an insurmountable technological problem. The real challenge lies in trust placed in tools and procedures. In an era of artificial intelligence, cyberattacks and digital forgeries, the state can no longer rely on informal digital methods. It must embrace modern tools, methods and channels to ensure every critical decision leaves a trace: who posted what, approved what, when, through which channel and with what security guarantees?
