Cameroon: what secure digital tools enable President Paul Biya to work remotely?
Overseeing national affairs from abroad—reviewing files, issuing directives, and approving administrative acts—requires far more than ordinary digital tools. For a Head of State, remote governance must rest on systems that guarantee:
- Confidentiality of classified information;
- Authenticity of the decision-maker’s identity;
- Integrity of official documents;
- Traceability of every instruction issued.
Following a statement by Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo, affirming that President Paul Biya continues to oversee governance from abroad—either in person or via known electronic channels—a critical question emerges: what secure digital infrastructure should the Presidency deploy to receive, process, validate, and archive sensitive documents while the Head of State is outside national borders?
While decrees may eventually appear on social media, the path they take—preparation, transmission, review, signing, registration, and preservation—remains opaque. This lack of transparency raises concerns about the security and authenticity of decisions made at a distance.
Institutional email: a non-negotiable foundation
A secure presidential workflow begins with the exclusive use of official email addresses under the @prc.cm domain.
Every senior collaborator—from the Secretary-General to civil cabinet members—should operate a personalized institutional inbox, such as [email protected], alongside functional mailboxes designated for specific units (e.g., [email protected]).
Personal accounts like Gmail or Yahoo must be off-limits for transmitting draft decrees, confidential memos, diplomatic correspondence, or state-sensitive instructions. The issue isn’t technical capacity—Gmail and Yahoo offer robust security—but governance control. The state cannot reliably:
- create or revoke access;
- enforce strong authentication;
- retain official correspondence;
- detect unauthorized logins;
- prevent auto-forwarding to personal inboxes;
- implement uniform security and archiving policies.
A dedicated presidential messaging system should integrate:
- SPF, DKIM, and DMARC protocols to prevent identity theft and phishing;
- End-to-end encryption for server-to-server communication;
- Centralized account lifecycle management.
Even with institutional email, highly sensitive documents should never be attached as files. Instead, the system should notify recipients that a document is available in a secure presidential portal.
A presidential document management platform
The Presidency requires a purpose-built electronic document management system (EDMS) for state affairs. Each file—whether a decree draft, policy memo, or diplomatic note—should be logged with:
- A unique reference identifier;
- The author’s identity;
- A confidentiality classification (Public, Internal, Confidential, Highly Sensitive);
- List of authorized viewers;
- Complete version history;
- Inline comments and approvals;
- A timestamped validation record;
- A full access audit trail.
This platform enables the President to:
- Review documents from a secure terminal;
- Add observations or request amendments;
- Approve proposals—without files being copied to multiple devices or shared via insecure channels.
For highly sensitive documents, the system should block local downloads, printing, text copying, or unauthorized transfers. It should also log every interaction: who accessed the file, when, from which device, and what changes were made.
Verifiable electronic signatures for presidential acts
A scanned image of a signature cannot authenticate a remote decree. Instead, digital signatures based on cryptographic certificates must be used to verify:
- The signatory’s identity;
- The document’s integrity;
- The exact time and date of validation;
- The absence of post-signature alterations.
Cryptographic keys for top-tier decisions must be stored in hardware security modules (HSMs)—not on regular computers, USB drives, or personal phones. Each use should require direct presidential authentication and generate a timestamped audit record.
For major decisions, the process should include multiple checks: presidential validation, technical signature verification, legal review, official registration, and public release.
Zero Trust architecture for remote access
A VPN alone is insufficient. The Presidency should adopt a Zero Trust framework, assuming no user, device, or network is inherently trustworthy.
Access requests should be evaluated based on:
- User identity;
- Device authentication;
- Geolocation;
- Document sensitivity level;
- Assigned access rights;
- Behavioral anomaly detection.
To access a presidential file, a collaborator may need:
- An institutionally managed device;
- A digital certificate;
- A hardware security key;
- A biometric scan on the device itself.
Dedicated institutional devices only
Personal phones and laptops must never handle presidential documents. Cabinet members and senior advisors should use institutionally owned, centrally managed devices configured to:
- Be fully encrypted;
- Receive mandatory security updates;
- Run only approved applications;
- Block personal use;
- Support remote wipe in case of loss;
- Auto-lock after short inactivity;
- Prohibit connections to unsecured public Wi-Fi.
A centralized endpoint management (EMM) system allows the administration to deploy updates, block risky apps, revoke devices, and remotely erase data if compromised.
Multi-factor authentication resistant to phishing
Passwords—even complex ones—are inadequate for presidential systems. Authentication should combine:
- A recognized institutional device;
- A personal PIN;
- A hardware security key (e.g., YubiKey);
- Optional local biometric verification.
While SMS-based one-time codes add layers, they remain vulnerable to interception. For the most critical accounts, physical keys and digital certificates offer stronger protection.
Staff must also undergo regular anti-phishing training to detect fraudulent messages, urgent scams, malicious links, and impersonation attempts targeting senior leaders.
WhatsApp: alert tool, not document channel
Despite end-to-end encryption, WhatsApp is not an official platform for transmitting presidential files. Risks include:
- Loss or espionage of devices;
- Screenshots or unauthorized transfers;
- Exposure via auto-backups;
- Use by former staff on personal devices.
The app can, however, be used to alert collaborators that a document is ready in the secure portal—for example: “File PRC/SG/2026/125 is available in your secure workspace for review.”
In short: Use WhatsApp to coordinate; the secure portal to transmit, process, decide, sign, and archive.
Secure government videoconferencing
Remote meetings between the President and advisors should occur via a dedicated, government-grade videoconferencing solution, offering:
- End-to-end encryption;
- Participant identity verification;
- Strict invitation controls;
- Prohibition of unauthorized recordings;
- Connection logging;
- Use of institutional devices only;
- Control over data hosting.
Public links, free accounts, and unvetted apps must never be used for sensitive discussions involving defense, diplomacy, appointments, or government arbitrations.
Document classification by sensitivity
Not all presidential documents carry equal risk. A four-tier classification system should guide handling:
- Public: for public dissemination;
- Internal: for government use only;
- Confidential: unauthorized release could harm public action;
- Highly Sensitive: defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each tier determines:
- Allowed transmission channels;
- Authorized personnel;
- Permissible devices;
- Printing and copying restrictions;
- Retention periods;
- Archiving protocols.
A public document may be sent via institutional email. A highly sensitive file, however, should only be accessible from a highly compartmentalized portal.
Complete traceability of every decision
Every consultation, modification, validation, or transmission must be automatically logged. The security journal should record:
- Who accessed the document;
- When and from which device;
- What changes were made;
- Who approved the final version;
- When it was officially recorded and published.
A security operations center (SOC) can monitor for anomalies—unusual logins, mass downloads, access from unrecognized devices, or unauthorized changes to official acts. This traceability is essential to reconstruct events in case of leaks, intrusions, or disputes over authenticity.
Avoid conflating official decisions with social media posts
Social media accounts of the Presidency are tools for public communication, not decision-making infrastructure. Before a decree appears on Facebook or X, it must have followed a secure path:
- Transmitted through an authorized channel;
- Authenticated by the competent authority;
- Verified for integrity;
- Timestamped upon validation;
- Archived in official records.
A visible signature on a posted image does not constitute proof in itself. The security lies in the complete, traceable process behind it.
Ten priority actions for the Presidency
To modernize remote governance, the Presidency should implement:
- Mandate institutional email under @prc.cm for all state business;
- Ban personal accounts (Gmail, Yahoo, etc.) for official communications;
- Deploy a presidential electronic document management system;
- Adopt a secure electronic signature system for presidential acts;
- Issue dedicated institutional phones and computers to authorized staff;
- Enforce multi-factor authentication resistant to phishing;
- Use WhatsApp solely for alerts and coordination;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Train staff regularly on espionage, phishing, and information leakage risks.
While no public evidence confirms the full deployment of these measures in Cameroon, they represent minimum safeguards for an institution tasked with remotely managing decisions that impact national finance, diplomacy, security, and continuity. At a time when digital trust is under siege, such infrastructure is essential to ensure that every presidential decision is authentic, traceable, and beyond reproach.
