In an era where digital transformation is reshaping governance, the question of secure remote work for heads of state has never been more critical. For President Paul Biya of Cameroon, the ability to manage state affairs from abroad hinges on robust, tamper-proof digital infrastructure. This raises a fundamental question: what secure digital tools should a modern presidency deploy to ensure confidentiality, authenticity, and continuity of governance?

Why ordinary digital tools fall short for presidential work
While messaging apps like WhatsApp or email services such as Gmail offer convenience, they lack the security layers required for presidential decision-making. The circulation of sensitive state documents—decrees, diplomatic correspondence, or high-level appointments—demands more than just encryption. It requires institutional control, non-repudiation, and comprehensive audit trails.
The recent statement by Minister of Higher Education Jacques Fame Ndongo underscored this reality. He confirmed that President Biya continues to oversee state affairs remotely, whether in person or via “known electronic means.” Yet, the debate extends beyond political narratives: what digital systems can ensure that every instruction, validation, and archival process remains unalterable and traceable when the head of state is abroad?
The case for an institutional email domain
A secure digital workspace begins with institutional email addresses under the official domain of the Presidency. Collaborators should use addresses like @prc.cm, with functional accounts for the General Secretariat, Civil Cabinet, and other departments. Personal accounts—whether Gmail, Yahoo, or others—must be avoided for state business.
The risks of personal email extend beyond security. State institutions lose control over:
- Creation and revocation of accounts;
- Device access and data retention;
- Authentication protocols and phishing vulnerabilities;
- Automated forwarding to unauthorized inboxes.
A domain-controlled email system would enforce:
- Multi-factor authentication (MFA) to prevent unauthorized access;
- SPF, DKIM, and DMARC protocols to block spoofing and phishing;
- Automated archiving of official exchanges;
- Real-time monitoring for suspicious logins or data exfiltration.
Even with these safeguards, highly sensitive documents should not be attached to emails. Instead, the system could notify recipients that a file is available in a secure presidential platform.
A presidential document management platform
Beyond email, a dedicated electronic document management system (EDMS) is essential. Each file should be logged with:
- A unique identifier;
- Author and editor details;
- Confidentiality classification (public, internal, confidential, or highly sensitive);
- Version history and approval workflows;
- Access logs and timestamps for every interaction;
- Restrictions on downloads, printing, or unauthorized sharing.
This platform would allow the President to:
- Review documents from a secure terminal;
- Add annotations or request revisions;
- Approve or reject proposals without exposing files to multiple devices;
- Ensure that only authorized personnel can view or modify documents.
Digital signatures with cryptographic guarantees
The validation of decrees or executive orders cannot rely on scanned signatures. A qualified electronic signature (QES) based on digital certificates would provide:
- Undeniable proof of the signatory’s identity;
- Assurance that the document has not been altered post-signature;
- A tamper-evident timestamped record of the validation;
- Cryptographic keys stored in hardware security modules (HSMs)—never on personal devices.
For critical decisions, the process could involve layered controls:
- Presidential validation;
- Technical verification of the signature;
- Legal review of the act;
- Official recording and public dissemination.
Zero Trust Architecture: beyond VPNs
While a Virtual Private Network (VPN) secures remote connections, it is not enough. A Zero Trust model assumes that no user, device, or network is inherently trustworthy. Access to presidential documents would require:
- Authentication via institutional devices;
- Multi-factor verification (password + physical token + biometrics);
- Location-based restrictions (e.g., blocking access from high-risk jurisdictions);
- Continuous behavioral analysis to detect anomalies.
For instance, accessing a highly sensitive file might require:
- A government-issued laptop with full-disk encryption;
- A hardware security key inserted into the device;
- A biometric scan for local authentication;
- A secure, encrypted connection to the presidency’s servers.
Exclusively institutional devices
Personal smartphones and laptops have no place in the handling of presidential documents. Collaborators in the Civil Cabinet, General Secretariat, and other key departments must use institutional devices managed by dedicated IT teams. These should feature:
- Full-disk encryption and automatic locking after inactivity;
- Centralized management for updates, app restrictions, and remote wipe capabilities;
- Prohibition of public Wi-Fi connections;
- Strict separation between professional and personal use.
In the event of loss or compromise, such devices could be remotely disabled, and all data erased to prevent unauthorized access.
Phishing-resistant authentication
Passwords alone are vulnerable. Authentication must combine:
- A recognized institutional device;
- A strong personal PIN; A physical security token (e.g., YubiKey);
- Optional local biometric verification.
SMS-based codes, while an additional layer, are still susceptible to SIM-swapping attacks. For the most sensitive accounts, hardware tokens and digital certificates offer superior protection. Staff should also undergo regular training to recognize phishing attempts, fraudulent urgency signals, and impersonation tactics.
The role of WhatsApp in presidential workflows
End-to-end encryption makes WhatsApp a useful tool for alerts and coordination—e.g., notifying a colleague that a document is ready for review in a secure platform. However, it is not suitable for transmitting sensitive files. Risks include:
- Exposure on lost or compromised devices;
- Screenshots or unauthorized forwarding;
- Inadequately protected backups;
- Use by former employees after leaving office.
The rule of thumb: Use WhatsApp to alert, the presidential platform to transmit.
Government-grade secure videoconferencing
Remote discussions between the President and advisors should occur via a dedicated, government-approved videoconferencing solution. This platform must ensure:
- End-to-end encryption of all communications;
- Strict participant authentication;
- Controlled invitation processes;
- Prohibition of unauthorized recordings;
- Data hosting within sovereign infrastructure;
- Comprehensive logging of all sessions.
Public links, free-tier accounts, and unvetted applications have no place in high-stakes government meetings.
Document classification and lifecycle management
Not all presidential documents carry the same risk. A classification policy could define four levels:
- Public: For public dissemination;
- Internal: For government use only;
- Confidential: Disclosure could harm public interests;
- Highly Sensitive: Defense, intelligence, diplomacy, or strategic appointments.
Each level dictates:
- Allowed transmission channels;
- Authorized personnel;
- Device and printing restrictions;
- Retention periods;
- Archival protocols.
Comprehensive audit trails: the backbone of accountability
Every interaction with a presidential document must be logged, including:
- Who accessed it and when;
- Device and location details;
- Any modifications made;
- Who approved the final version;
- When it was published and by whom.
A dedicated security operations center (SOC) could monitor for anomalies—such as unusual download patterns, logins from unrecognized devices, or unauthorized edits. This traceability ensures that in the event of a leak or dispute, the full chain of custody can be reconstructed.
Ten priorities for the Presidency’s digital security
To modernize its remote governance capabilities, the Presidency should implement these ten measures:
- Mandate institutional email under the @prc.cm domain;
- Ban the use of personal Gmail, Yahoo, or similar accounts for state business;
- Deploy a presidential electronic document management system;
- Adopt a government-grade electronic signature solution;
- Provide exclusively institutional devices to collaborators;
- Enforce phishing-resistant multi-factor authentication;
- Reserve WhatsApp for alerts and coordination only;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Train staff regularly on spying risks, phishing, and data leakage.
While no public evidence confirms Cameroon’s Presidency currently uses all these measures, they represent the minimum standards for a head of state governing remotely. The stakes are high: financial integrity, diplomatic secrecy, national security, and the uninterrupted functioning of the state all depend on digital trust.
These challenges will take center stage at E-Gov’A 2026, the E-Government Africa Summit, Expo & Awards, scheduled for October 14–16 in Yaoundé. Under the theme “Artificial Intelligence and E-Governance: Building Efficient Public Services in a Cashless, Paperless Africa,” the event will convene policymakers, technologists, and development partners to explore how digital innovation can strengthen governance across the continent.
The question is not merely whether a president can work from Geneva, Paris, or New York. It is whether the tools used can authenticate decisions, protect state secrets, trace instructions, and prevent forgery in the President’s name. In an age of AI-driven deepfakes and cyber threats, the answer lies in robust, modern, and fully auditable digital systems.
