July 29, 2026
477c14dc-410b-4fdd-8693-6e486b5a70d4

Cameroon’s president: how secure digital tools enable remote governance

In today’s interconnected world, accessing state documents, coordinating with advisors, and approving administrative decisions remotely is technically feasible. Yet when it comes to the Head of State, remote governance cannot rely on ordinary digital tools. It demands systems that guarantee information confidentiality, decision-maker authentication, document integrity, and full traceability of every instruction.

The debate on remote governance resurfaced after a statement by Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo. He refuted claims of a “vacancy” at the helm of the state by asserting that President Paul Biya continues to review files and issue directives—either in person or via “electronic means known to all.” But this raises a critical question: what secure digital tools should a modern presidency use to receive, review, approve, and archive sensitive documents when the head of state is abroad?

Posting a decree on Facebook, X, or the official presidency website is merely the final step in public communication. It reveals nothing about how the document was drafted, transmitted, reviewed, signed, registered, or preserved.

Mandatory institutional email for all presidential communications

Every communication involving state matters must originate from official email addresses under the presidency’s domain. Advisors should use personalized accounts like [name]@prc.cm and functional addresses for departments such as the General Secretariat, Civil Cabinet, and others. For instance, [email protected] should be prioritized for official correspondence.

Personal accounts like Gmail or Yahoo are unsuitable for transmitting draft decrees, confidential memos, diplomatic correspondence, or state-critical instructions. Beyond technical security limitations, these accounts fall outside state control—ownership, device access, message retention, and account deactivation after an official’s departure remain unregulated.

A professional messaging system under @prc.cm would enable:

  • Real-time creation and revocation of advisor accounts;
  • Enforced multi-factor authentication;
  • Secure retention of official exchanges;
  • Detection of suspicious login attempts;
  • Blocking automatic forwarding to personal inboxes;
  • Uniform security and archiving policies.

This system must integrate SPF, DKIM, and DMARC protocols to prevent identity theft and phishing. All server-to-server communications should be encrypted. However, even institutional emails are inadequate for transmitting highly sensitive documents as attachments. Instead, they should notify recipients that a file is available in a secure presidential platform.

A dedicated presidential document management platform

A specialized electronic document management system is essential for state affairs. Each file should be logged with:

  • A unique reference identifier;
  • The author’s identity;
  • A confidentiality classification;
  • Authorized access permissions;
  • Document versions and revisions;
  • Comments and approvals;
  • Validation timestamps;
  • A complete access history.

With this system, the president could review documents on a secure terminal, add annotations, request amendments, or approve proposals without files being copied to multiple devices or personal inboxes. For highly sensitive files, the platform should restrict local downloads, printing, text copying, or unauthorized transfers. It should also track who accessed the document, when, from which device, and what changes were made.

Verifiable electronic signatures for presidential decisions

Remote validation of decrees or decisions must go beyond scanned images of a signature. An electronic signature based on digital certificates ensures:

  • The signatory’s identity;
  • Document integrity;
  • Validation date and time;
  • Post-signature tamper-proofing.

The cryptographic key for signing critical documents must be stored in a highly secure hardware module—not on ordinary computers, USB drives, or personal phones. Its use should require direct presidential authentication and generate a timestamped log entry. For major decisions, the process could include multiple layers: presidential approval, technical signature verification, legal review, official registration, and public dissemination.

Zero Trust architecture: securing remote access

While a Virtual Private Network (VPN) secures connections between officials abroad and presidential servers, it should not be the sole safeguard. A Zero Trust model assumes no user, device, or network is inherently trustworthy. Access requests must be verified based on:

  • User identity;
  • Device authentication;
  • Connection location;
  • Document sensitivity level;
  • Assigned user permissions;
  • Behavioral anomalies during the session.

Accessing a presidential file could require an institutional computer, digital certificate, encrypted connection, physical security key, and local biometric verification on the device.

Institutionally managed devices only

Presidential documents must never be accessed from personal phones or computers. Devices issued to the Civil Cabinet, General Secretariat, and other relevant departments should be:

  • Fully encrypted;
  • Regularly updated;
  • Restricted to authorized applications;
  • Segregated from personal use;
  • Remotely wipeable in case of loss;
  • Automatically locked after inactivity;
  • Prohibited from connecting to unsecured public Wi-Fi.

A centralized device management system would allow the administration to deploy updates, block dangerous apps, revoke compromised devices, and remotely erase data if necessary.

Phishing-resistant authentication

Passwords alone—even complex ones—are insufficient for accessing presidential files. Authentication should combine:

  • An institutional device;
  • A personal PIN;
  • A physical security key;
  • Optional local biometric verification.

While SMS codes add security, they remain vulnerable to attacks. For high-risk accounts, physical keys and digital certificates offer stronger phishing resistance. Staff must also be trained to recognize fraudulent messages, urgent scams, malicious links, and impersonation attempts.

WhatsApp: useful for alerts, not document transmission

WhatsApp’s end-to-end encryption protects message content during transmission, but it is not an official document management tool. Risks include:

  • Lost or compromised phones;
  • Screenshots;
  • Unauthorized transfers;
  • Linked device backups;
  • Insufficiently protected cloud backups;
  • Personal phones of former staff.

The app lacks mechanisms for file classification, access control, versioning, validation, electronic signing, or archiving. Instead, it could be used to alert colleagues that a document is ready for review in the secure platform—for example: “File PRC/SG/2026/125 is available in your secure workspace for review.” The document itself should never be attached.

Secure government videoconferencing

Remote meetings between the president and advisors should use a dedicated, government-grade videoconferencing solution offering:

  • Encrypted communications;
  • Participant identification;
  • Strict invitation controls;
  • Prohibition of unauthorized recordings;
  • Connection logging;
  • Exclusive use of institutional devices;
  • Data hosting under state control.

Public links, free accounts, and unvetted apps must never be used for defense, diplomacy, appointments, or government arbitrations.

Classifying documents by sensitivity

Not all presidential documents carry equal risk. A classification policy could define four tiers:

  • Public: intended for public release;
  • Internal: restricted to government services;
  • Confidential: disclosure could harm public action;
  • Highly sensitive: related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each tier dictates transmission channels, authorized personnel, device requirements, printing permissions, retention periods, and archiving protocols. A public document might be sent via professional email, while a highly sensitive one should only be accessible through a tightly secured platform.

Full traceability for every decision

Every consultation, modification, approval, or transmission must be automatically logged, detailing:

  • The user who accessed the document;
  • The access time;
  • The device used;
  • Changes made;
  • The approver of the final version;
  • The registration and publication timestamps and actors.

A security operations center could detect unusual logins, mass downloads, unauthorized device access, or suspicious modifications. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over a decision’s authenticity.

Distinguishing official decisions from social media posts

Presidential Facebook pages and X accounts are tools for public communication, not for preparing and validating decisions. Before a decree is posted online, it must follow a secure process:

  • Transmission via an authorized channel;
  • Authentication of the competent authority;
  • Assurance the final version is unaltered;
  • A timestamped validation;
  • Preservation of the original in official archives.

A visible signature on a published image is not, by itself, sufficient digital proof. Security lies in the entire process preceding publication.

Ten priority measures for the presidency

The presidency should implement these ten actions immediately:

  1. Mandate professional email under @prc.cm;
  2. Ban personal accounts like Gmail and Yahoo for state business;
  3. Deploy a presidential electronic document management platform;
  4. Introduce a secure institutional electronic signature system;
  5. Provide exclusively professional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Restrict WhatsApp to alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security operations center;
  10. Train staff regularly on espionage, phishing, and information leaks.

While no public evidence confirms Cameroon’s presidency currently uses all these measures, they represent the minimum standards required for an institution handling remote state affairs—especially those involving finance, diplomacy, security, and national continuity. These challenges of secure document transmission, electronic signatures, data sovereignty, and digital continuity will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, taking place October 14–16, 2026, at the Palais des Congrès in Yaoundé. The event, under the patronage of the Ministry of Posts and Telecommunications, will explore the theme: “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa.”

The question is not whether a president can work from Geneva, Paris, or New York. The real challenge is whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in the president’s name.

Modern tools and accountability

Remote presidential work is not an insurmountable technological hurdle. The true challenge lies in trusting the tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must adopt modern tools to ensure that every critical decision leaves a trace: who posted what, approved what, when, through which channel, and with what security guarantees?