When foreign officials or heads of state must handle sensitive state matters from abroad, the tools they use are anything but ordinary. Consulting classified files, coordinating with advisors, issuing decrees, or approving administrative acts remotely is technically feasible—but for the President of the Republic, this process requires uncompromising digital security. It demands systems that guarantee the confidentiality of information, the authenticity of the decision-maker, the integrity of documents, and full traceability of every instruction issued.
Recent statements by Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo, have reignited discussion around remote governance. He emphasized that President Paul Biya continues to oversee state affairs from abroad, either in person or through “electronic means known to all.” While this addresses political concerns over continuity of leadership, it raises a critical operational question: What secure digital infrastructure should a modern presidency deploy to receive, review, approve, and archive sensitive documents when the head of state is outside national territory?
Publication on social networks or official websites is merely the final step in communication. It reveals nothing about the internal process—how a document was drafted, transmitted, reviewed, signed, filed, or stored. Ensuring full transparency and security requires a robust digital ecosystem that leaves no room for ambiguity or compromise.
Institutional email under the @prc.cm domain
The foundation of secure remote governance begins with official email addresses tied to the Presidency’s domain. All presidential staff—from advisors to department heads—should use institutional accounts such as [email protected] or [email protected], rather than personal services like Gmail or Yahoo.
Personal accounts, while convenient, fall outside state control. Administrations cannot guarantee their creation, security settings, device access, message retention, or proper deactivation when personnel change roles. A dedicated @prc.cm system enables:
- Centralized account management: creation, modification, and revocation of access;
- Strong authentication: mandatory multi-factor authentication;
- Secure storage: preservation of all official exchanges;
- Threat detection: identification of suspicious logins;
- Policy enforcement: prevention of auto-forwarding to personal inboxes;
- Compliance tracking: unified security and archiving policies.
To prevent identity theft and phishing, the system should integrate SPF, DKIM, and DMARC protocols, and enforce end-to-end encryption for server-to-server communication. Even with a secure institutional inbox, highly sensitive documents should not be sent as email attachments. Instead, the system can notify recipients that a file is available in a secure presidential portal.
A presidential document management platform
A dedicated electronic document management system (EDMS) is essential for handling state affairs. Each file should be registered with:
- Unique identifier for tracking;
- Author identity for accountability;
- Confidentiality level to determine access rights;
- List of authorized viewers to enforce need-to-know;
- Version history to track revisions;
- Commentary and approvals for transparency;
- Validation timestamp for legal certainty;
- Full audit trail of every access and modification.
This platform allows the President to review documents from a secure terminal, add notes, request changes, or approve proposals without ever downloading files to local devices or sending them through unsecured channels. For the most sensitive files, the system can block local downloads, printing, text copying, or unauthorized transfers. It also logs who accessed a document, when, from which device, and what changes were made—ensuring full accountability and preventing leaks or tampering.
Electronic signature with verifiable validity
A scanned image of a signature is not sufficient for remotely validating decrees or decisions. A qualified electronic signature based on digital certificates ensures:
- Signatory identity verification;
- Document integrity—no unauthorized changes;
- Timestamp authentication—date and time of validation;
- Tamper detection—any post-signature alteration is flagged.
The cryptographic key used for signing the most critical acts must be stored in a hardware security module (HSM)—never on a regular computer, USB drive, or personal device. Access to this key should require direct biometric or multi-factor authentication from the President, with each use generating a time-stamped audit record. For major decisions, a multi-layered process can include presidential approval, technical signature verification, legal review, official registration, and public publication.
Zero Trust architecture for remote access
A Virtual Private Network (VPN) can secure the connection between a traveling official and presidential servers—but it should not be the sole safeguard. A Zero Trust framework assumes no user, device, or network is inherently trustworthy. Every access request is evaluated based on:
- User identity;
- Device legitimacy (institutional and updated);
- Connection location;
- Document sensitivity;
- Assigned access rights;
- Behavioral analysis during the session.
Accessing a presidential file may require multiple factors simultaneously: an authorized institutional device, a digital certificate, encrypted connection, a physical security key, and a local biometric scan. This layered approach minimizes risks of unauthorized access, even if credentials are compromised.
Institutional devices only—no personal use
Sensitive presidential documents must never be accessed from personal phones or computers. Official staff—including members of the Civil Cabinet, General Secretariat, and relevant services—should be equipped with institutionally owned, centrally managed devices that:
- Are fully encrypted to protect data at rest and in transit;
- Receive regular security updates to patch vulnerabilities;
- Run only approved applications, with no side-loading of software;
- Are segregated from personal use;
- Can be remotely wiped if lost or stolen;
- Auto-lock after short inactivity;
- Are blocked from public Wi-Fi to prevent eavesdropping.
A centralized device management system allows the administration to deploy updates, block unsafe apps, revoke devices, and remotely erase data in case of compromise—ensuring full control over the digital perimeter.
Anti-phishing authentication protocols
A strong password alone is insufficient for accessing presidential systems. Authentication should combine multiple factors:
- Institutional device (recognized and managed);
- Personal PIN or password;
- Physical security key (e.g., YubiKey);
- Optional biometric verification (fingerprint or facial recognition).
While SMS-based one-time codes add a layer of security, they remain vulnerable to SIM swapping and interception. For high-risk accounts, physical keys and digital certificates offer superior resistance to phishing attacks. Staff should also undergo regular training to detect fraudulent messages, urgent scams, malicious links, and impersonation attempts—especially when mimicking senior officials.
WhatsApp: useful for alerts, not for documents
Though widely used in Cameroon—including within government—WhatsApp’s end-to-end encryption does not qualify it as an official platform for managing presidential documents. Risks include:
- Loss or theft of unsecured devices;
- Screenshots or unauthorized forwarding;
- Backups on insecure cloud services;
- Exposure on personal devices of former staff;
- Lack of version control, signing, or archiving capabilities.
WhatsApp can, however, serve as a coordination tool—alerting the President that a file is ready for review in the secure portal. For example:
“The document referenced PRC/SG/2026/125 is now available in your secure workspace for review.”
The file itself should never be attached. The rule is clear: Use WhatsApp to alert and coordinate; the presidential platform to transmit, review, decide, sign, and archive.
Secure government videoconferencing
Remote meetings between the President and advisors require a dedicated, government-grade videoconferencing solution that ensures:
- End-to-end encryption of all communications;
- Participant authentication with verified identities;
- Strict invitation controls to prevent unauthorized access;
- Prohibition of unauthorized recordings;
- Comprehensive session logging;
- Use of institutional devices only;
- Controlled data hosting within national infrastructure.
Public links, free-tier accounts, and unvetted applications are unsuitable for discussions involving defense, diplomacy, nominations, or government arbitration.
Document classification by sensitivity level
Not all presidential documents carry the same risk. A clear classification policy should define four tiers:
- Public: intended for public dissemination;
- Internal: working documents for government services;
- Confidential: disclosure could harm public action;
- Highly Sensitive: defense, intelligence, diplomacy, or strategic appointments.
Each level dictates the transmission channel, authorized personnel, permissible devices, printing rights, retention periods, and archiving methods. A public document may be sent via institutional email, but a highly sensitive file should only be accessible through a highly secured, compartmentalized platform.
Full traceability of every decision
Every interaction with a document—consultation, editing, approval, or transmission—must be automatically logged. The security journal should capture:
- Who accessed the document;
- When the access occurred;
- From which device and location;
- What changes were made;
- Who approved the final version;
- When it was officially recorded and published.
A dedicated security operations center can monitor for unusual activity—such as mass downloads, logins from unrecognized devices, or abnormal document modifications—and trigger alerts. This traceability also enables reconstruction of events in case of leaks, intrusions, or disputes over the authenticity of a decision.
Distinguish official decisions from social media posts
The President’s social media pages (Facebook, X) serve to inform the public swiftly—but they are not the systems used to prepare or validate decisions. Before a decree is published online, it must have followed a secure internal process:
- The document was transmitted through an authorized channel;
- The authority was authenticated;
- The final version was unaltered;
- The validation was time-stamped;
- The original is preserved in official archives.
A visible signature on a published image does not constitute digital proof. The security lies in the entire process that preceded publication.
Ten priority actions for the Presidency
To modernize remote governance while ensuring security and transparency, the Presidency could implement the following ten measures:
- Mandate institutional email under @prc.cm for all state business;
- Ban personal email accounts (Gmail, Yahoo, etc.) for official correspondence;
- Deploy a secure presidential document management platform for drafting, reviewing, and approving files;
- Introduce qualified electronic signatures with hardware-backed keys;
- Provide exclusively institutional phones and computers to authorized staff;
- Enforce multi-factor authentication resistant to phishing;
- Reserve WhatsApp for alerts and coordination only;
- Classify documents by sensitivity level and apply corresponding protocols;
- Centralize access logs in a security monitoring center;
- Conduct regular staff training on espionage, phishing, and data leaks.
While no public evidence confirms that all these measures are currently in place, they represent the minimum security standards expected from an institution responsible for managing state finances, diplomacy, security, and continuity—especially when leadership operates remotely.
The stakes of secure governance in the digital age
Remote presidential work is no longer a technological challenge—it is a trust and accountability challenge. In an era of artificial intelligence, cyberattacks, and digital forgery, a state cannot rely on informal digital practices. It must adopt modern tools and procedures so that every critical decision leaves a verifiable trace: who initiated what, who approved it, when, through which channel, and under what security guarantees.



