Yaoundé — In an era where digital technology permeates every facet of governance, a critical question arises: How can a Head of State like President Paul Biya of Cameroon ensure the continuity of state affairs while working remotely? The challenge goes beyond mere connectivity; it demands a robust framework of secure digital tools capable of safeguarding sensitive information, verifying identities, preserving document integrity, and maintaining an unbroken chain of command.
This debate gained renewed momentum following remarks by Minister of Higher Education Pr Jacques Fame Ndongo, who dismissed rumors of a “vacancy” at the helm of the state. He emphasized that President Biya continues to oversee national matters, either in person or via established electronic channels. Yet, this raises a fundamental query: What secure digital infrastructure should Cameroon’s Presidency deploy to handle, validate, and archive critical documents when the Head of State is abroad?
The mere publication of a decree on social media represents the final step in a much longer, invisible process. It offers no insight into how the document was drafted, transmitted, reviewed, signed, or preserved. To address this gap, the Presidency must adopt a suite of secure, institutionally managed digital solutions.
institutional email addresses under the @prc.cm domain
The first pillar of a secure remote governance system is the exclusive use of official email addresses tied to the Presidency’s domain, @prc.cm. Collaborators should have personalized accounts, such as [email protected], alongside functional addresses for general secretariats and civil cabinets. Personal accounts like Gmail or Yahoo must be off-limits for state affairs, including decree drafts, classified memos, or diplomatic correspondence.
The risks associated with personal accounts extend beyond technical vulnerabilities. State authorities lose control over their creation, access management, message retention, and deactivation upon staff departures. A professional email system under @prc.cm would enable:
- Centralized account creation and revocation for staff;
- Mandatory multi-factor authentication;
- Secure archiving of official exchanges;
- Real-time detection of suspicious login attempts;
- Prevention of automatic forwarding to personal inboxes;
- Uniform security and retention policies across all accounts.
To further fortify this system, the domain should implement SPF, DKIM, and DMARC protocols to thwart identity theft and phishing. All inter-server communications must be encrypted. However, even a secure institutional email should not serve as the primary channel for transmitting highly sensitive documents. Instead, it should direct recipients to a dedicated presidential platform where the actual files reside.
a presidential electronic document management platform
The Presidency requires a specialized electronic document management system designed for state affairs. Each dossier should be logged with:
- A unique reference identifier;
- The author’s authenticated identity;
- A confidentiality classification label;
- Designated user access permissions;
- Version control and revision history;
- Embedded comments and approval workflows;
- A timestamped validation date;
- A complete audit trail of all accesses.
Through this platform, the President could review a document on a secured terminal, add annotations, request revisions, or grant approval—without ever downloading or copying the file to personal devices. For top-secret files, the system should block local downloads, printing, text copying, or unauthorized transfers. Every interaction—who accessed it, when, from which device, and what changes were made—would be meticulously recorded.
presidential electronic signatures with full verifiability
A scanned image of a signature is insufficient for remotely validating decrees or decisions. Instead, the Presidency should deploy an electronic signature system based on digital certificates. This ensures:
- Unambiguous identification of the signatory;
- Guaranteed document integrity;
- A tamper-proof timestamp of validation;
- Automated detection of post-signature alterations.
Cryptographic keys used for high-stakes signatures should be stored in hardware security modules, not on ordinary computers, USB drives, or personal phones. Each use of these keys must require direct biometric authentication from the President and generate a time-stamped audit log. For major decisions, the process could include multiple layers: presidential approval, technical signature verification, legal review, official registration, and public dissemination.
zero trust architecture for remote access
While VPNs provide a basic layer of security for remote connections, they should not be the sole safeguard. The Presidency could adopt a Zero Trust model, which assumes no user, device, or network is inherently trustworthy. Every access request would be evaluated based on:
- The user’s verified identity;
- The device’s compliance status;
- The geographic location of the connection;
- The sensitivity level of the requested document;
- The user’s assigned access rights;
- Behavioral anomalies during the session.
Access to presidential files could require a combination of institutional hardware, digital certificates, encrypted connections, physical security keys, and local biometric verification on the device.
exclusively institutional devices for presidential staff
Personal phones and computers should never be used to handle presidential documents. Staff in the Civil Cabinet, General Secretariat, and relevant departments must rely solely on equipment issued and managed by the Presidency. These devices must feature:
- Full-disk encryption;
- Automatic, regular software updates;
- Restrictions to authorized applications only;
- Strict separation from personal use;
- Remote wipe capabilities in case of loss;
- Automatic lock after brief inactivity;
- Prohibition of connections to unsecured public Wi-Fi networks.
A centralized mobile device management system would allow administrators to push updates, block hazardous apps, revoke devices, and remotely erase data in the event of theft or compromise.
anti-phishing authentication protocols
Passwords, even complex ones, are no longer sufficient. Authentication should integrate multiple factors:
- An officially issued, recognized device;
- A personalized PIN code;
- A physical security key;
- A local biometric scan (fingerprint or facial recognition).
While SMS-based codes can add a layer of security, they remain vulnerable to interception. For the most sensitive accounts, physical keys and digital certificates offer superior resistance to phishing attempts. Staff should also undergo regular training to recognize fraudulent messages, urgent scams, malicious links, and impersonation tactics targeting hierarchical superiors.
WhatsApp: useful for alerts, not for document transmission
WhatsApp enjoys widespread use in Cameroon, even within government circles, thanks to its end-to-end encryption. However, this does not qualify it as a secure platform for handling presidential documents. Risks persist through lost phones, screen captures, unauthorized transfers, unsecured backups, or lingering access after staff departures. Moreover, WhatsApp lacks the features necessary to classify documents, manage permissions, track versions, record approvals, or ensure legal archiving.
The app could, however, serve as a notification tool. For example, a collaborator might send the message: “Dossier PRC/SG/2026/125 is now available in your secure workspace for review.” The actual document should never be attached to the conversation. The guiding principle: WhatsApp for alerts and coordination; the presidential platform for secure transmission, review, decision-making, signing, and archiving.
government-grade secure videoconferencing
Remote discussions between the President and advisors should occur via a dedicated, government-secured videoconferencing platform. This solution must ensure:
- Encrypted audio and video streams;
- Mandatory participant identification;
- Strict control over meeting invitations;
- Prohibition of unauthorized recordings;
- Retention of connection logs;
- Exclusive use of institutional devices;
- Controlled data hosting within national borders.
Public links, free accounts, and unvetted apps should never be used for sensitive meetings involving defense, diplomacy, appointments, or government arbitration.
classifying documents by sensitivity level
Not all presidential documents carry the same risk. A classification policy could divide files into four tiers:
- Public: intended for public dissemination;
- Internal: internal working documents for state services;
- Confidential: disclosure could harm public action;
- Highly Sensitive: relates to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level dictates the transmission channel, authorized personnel, permissible devices, printing rights, retention periods, and archival procedures. A public document might be sent via professional email, while a highly sensitive file should only be accessible through a tightly controlled platform.
comprehensive audit trails for every decision
Every consultation, modification, approval, or transmission must be automatically logged. A security journal should capture:
- The identity of the person accessing the document;
- The exact time and date of access;
- The device and location from which the access occurred;
- Any modifications made to the document;
- The identity of the final approver;
- The time of official registration and publication.
A dedicated security operations center could monitor for unusual activity—such as logins from unrecognized devices, mass document downloads, or unauthorized modifications—and trigger immediate alerts. This traceability is invaluable in reconstructing events during leaks, intrusions, or disputes over the authenticity of a decision.
distinguishing official decisions from social media posts
While the Presidency’s Facebook and X accounts are valuable for rapid public communication, they are not the systems used to prepare or validate decisions. Before a decree is published online, it must traverse a secure, authenticated workflow:
- The document was transmitted via an authorized channel;
- The issuing authority was verified;
- The final version remained unaltered;
- The approval was time-stamped;
- The original is preserved in official archives.
A visible signature on a social media image does not constitute definitive proof. The integrity of the decision rests on the entire preceding process.
ten priority measures for the presidency
To modernize remote governance, the Presidency could implement ten essential measures:
- Mandate the use of professional email addresses under the @prc.cm domain;
- Prohibit personal accounts like Gmail or Yahoo for state business;
- Deploy a specialized presidential electronic document management platform;
- Introduce a secure, institutionally managed electronic signature system;
- Issue exclusively institutional phones and computers to staff;
- Enforce multi-factor authentication resistant to phishing;
- Reserve WhatsApp for alerts and coordination only;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Provide regular cybersecurity and anti-phishing training for staff.
While no public evidence confirms that all these measures are currently in place, they represent the minimum standards required for an institution managing remotely sensitive files that impact national finances, diplomacy, security, and governance continuity.
The stakes are clear: It is not enough to ask whether a president can work from abroad. The true challenge lies in ensuring that every tool used authenticates decisions, protects state secrets, traces instructions, and prevents unauthorized alterations or forgeries in the President’s name.



