The ability to review files, exchange with teams, and approve decisions from abroad is now a technical reality. Yet when it comes to the Head of State, distance working cannot rely on ordinary digital tools. It demands systems that ensure information confidentiality, identity verification, document integrity, and traceability of every directive.
The debate was reignited by a statement from Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo. He dismissed claims of a “vacancy” at the top of the State, asserting that President Paul Biya continues to oversee files and issue directives—either in person or through “electronic means known to all.” This raises a critical question: what secure digital tools should a modern presidency use to receive, review, process, approve, and archive sensitive documents when the President is abroad?
Posting a decree on Facebook, X, or the Presidency’s website is merely the final step in public communication. It reveals nothing about how the document was prepared, transmitted, reviewed, signed, recorded, or preserved.
Professional email under the @prc.cm domain
The first requirement is the systematic use of official email addresses linked to the Presidency’s domain. Staff should have personal addresses like [email protected], along with functional accounts for the General Secretariat, Civil Cabinet, and other departments—such as [email protected].
Personal accounts from Gmail, Yahoo, or other public services must never be used for state-related correspondence. The issue isn’t just technical security; it’s governance. Personal accounts fall outside state control—creation, device access, message storage, recovery, and deactivation aren’t always managed by the administration.
A professional email system under @prc.cm would enable:
- creation and revocation of staff accounts;
- mandatory multi-factor authentication;
- secure storage of official exchanges;
- detection of suspicious logins;
- blocking automatic forwarding to personal inboxes;
- consistent security and archiving policies.
This system must prevent identity theft and phishing using SPF, DKIM, and DMARC protocols, and encrypt server-to-server communications. Even secure institutional emails should not transmit highly sensitive documents as attachments. Instead, they should notify recipients that a file is available in a secure presidential platform.
A presidential platform for document management
The Presidency needs an electronic document management system tailored to state affairs. Each file should include:
- a unique reference;
- author identification;
- confidentiality level;
- authorized viewers;
- document versions;
- comments and approvals;
- validation date;
- full access history.
This allows the President to review documents from a secure terminal, add notes, request changes, or approve proposals without files being copied across devices or sent to personal emails. For the most sensitive files, the platform must prevent local downloads, printing, text copying, or unauthorized transfers.
A verifiable presidential electronic signature
Remote approval of decrees or decisions shouldn’t rely on a scanned image of a signature. An electronic signature based on digital certificates must verify:
- the signer’s identity;
- document integrity;
- approval date and time;
- post-signature tampering.
The cryptographic key for signing critical documents must be stored in a highly secure hardware module—not on a regular computer, USB drive, or personal phone. Its use should require direct presidential authentication and generate a timestamped audit trail. For major decisions, the process could include multiple checks: presidential validation, technical signature verification, legal review, official registration, and publication.
Zero Trust access for remote work
A virtual private network (VPN) secures connections but shouldn’t be the sole safeguard. The Presidency should adopt a Zero Trust architecture, assuming no user, device, or network is inherently trustworthy. Access requests must be verified based on:
- user identity;
- device used;
- connection location;
- document sensitivity level;
- user permissions;
- behavioral patterns during the session.
Accessing presidential files could require an institutional device, digital certificate, encrypted connection, physical security key, and a local biometric check on the device.
Institutional devices only for state business
Presidential files must never be accessed from personal phones or computers. Staff in the Civil Cabinet, General Secretariat, and relevant departments should use devices owned and managed by the institution. These devices must be:
- fully encrypted;
- regularly updated;
- limited to approved applications;
- segregated from personal use;
- remotely wipeable if lost;
- auto-locked after inactivity;
- blocked from unsecured public Wi-Fi.
A centralized terminal management system would allow updates, blocking dangerous apps, revoking devices, and remote data deletion in case of theft or compromise.
Phishing-resistant authentication
A password—even a complex one—should never suffice for accessing presidential files. Authentication must combine:
- an institutional device;
- a personal code;
- a physical security key;
- optional local biometric verification.
SMS codes can add security but remain vulnerable to attacks. For high-risk accounts, physical keys and digital certificates offer stronger protection against phishing. Staff should also be trained to recognize fake messages, fraudulent urgent requests, malicious links, and attempts to impersonate superiors.
WhatsApp for alerts, not file transfers
WhatsApp is widely used in Cameroon, including in government circles. Its end-to-end encryption protects message content during transmission, but it’s not an official document management platform.
A file sent via WhatsApp risks exposure through:
- a lost or compromised phone;
- screenshot captures;
- unauthorized forwarding;
- backups with weak protection;
- personal devices of former staff.
WhatsApp lacks mechanisms for document classification, access control, version tracking, electronic signatures, or administrative archiving. It could, however, be used to notify that a file is available in a secure space—e.g., “The file PRC/SG/2026/125 is ready for review in your secure workspace.” The document itself should never be attached.
Secure government videoconferencing
Remote exchanges between the President and teams should use a dedicated secure platform offering:
- encrypted communications;
- verified participant identification;
- strict invitation controls;
- prohibition of unauthorized recordings;
- connection logs retention;
- exclusive use of institutional devices;
- data hosting control.
Public links, free accounts, and unvetted apps must never be used for defense, diplomacy, appointments, or government arbitrations.
Classifying documents by sensitivity
Not all presidential documents carry the same risk. A classification policy could define four categories:
- Public: for public dissemination.
- Internal: working documents for state services.
- Confidential: disclosure could harm public action.
- Highly sensitive: defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level determines the allowed transmission channel, authorized personnel, permissible devices, printing options, retention duration, and archiving methods. Public documents may be sent via professional email; highly sensitive ones should only be accessible on a tightly controlled platform.
Complete traceability for every decision
Every consultation, modification, validation, or transfer must be automatically logged. Security logs should include:
- who accessed the file;
- when and from which device;
- what changes were made;
- who approved the final version;
- when it was registered and published.
A security operations center could detect unusual logins, bulk downloads, access from unrecognized devices, or unauthorized modifications to official acts. This traceability would help reconstruct events in case of leaks, intrusions, or disputes over authenticity.
Distinguishing official decisions from social media posts
The Presidency’s Facebook and X accounts are tools for public information, not systems for preparing or approving decisions. Before a decree is published online, it must follow a secure process:
- transmitted through authorized channels;
- authenticated by competent authorities;
- verified as unaltered;
- timestamped upon validation;
- preserved in official archives.
A visible signature on an image shared online isn’t sufficient proof. Security lies in the entire preceding process.
Ten priority measures for the Presidency
The Presidency could implement these ten actions:
- Mandate professional email under the @prc.cm domain.
- Ban personal Gmail, Yahoo, and similar accounts for state business.
- Deploy a presidential electronic document management platform.
- Introduce secure institutional electronic signatures.
- Provide exclusively professional phones and computers.
- Enforce multi-factor authentication resistant to phishing.
- Restrict WhatsApp to alerts and coordination.
- Classify documents by sensitivity levels.
- Centralize access logs in a security operations center.
- Train staff regularly on espionage, phishing, and information leaks.
While no public information confirms the full implementation of these measures in Cameroon, they represent the minimum standards a presidency handling remote state affairs should adopt. The stakes include secure document transmission, electronic signatures, data sovereignty, and digital continuity of the State.
These themes will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, at the Yaoundé Congress Palace. The event, organized under the high patronage of the Ministry of Posts and Telecommunications, will explore how artificial intelligence and e-governance can build efficient public services in a cashless, paperless Africa.
The key question isn’t whether a president can work from Geneva, Paris, or New York. The real challenge is ensuring the tools used authenticate decisions, protect state secrets, trace directives, and prevent anyone from altering, diverting, or fabricating an act in the President’s name.
Modern tools and accountability
Remote presidential work isn’t an insurmountable technological challenge. The true hurdle is trust in the tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the State must adopt modern methods. Every major decision must leave a trace: who posted what, approved what, when, through which channel, and with what security guarantees?



