July 29, 2026

The Panafrican Press

English-language platform committed to rigorous, independent journalism across the African continent.

Secure remote presidential work in Cameroon

Managing state affairs from abroad isn’t just possible—it’s increasingly necessary. Yet when the task involves the President of the Republic, ordinary digital tools fall short. Confidentiality, identity verification, document integrity, and traceability of every instruction must be flawless. The debate over remote governance was reignited by a recent statement from Cameroon’s Minister of Higher Education, Professor Jacques Fame Ndongo, who confirmed that President Paul Biya continues to oversee national matters, whether in person or through secure electronic channels.

But what specific digital infrastructure should the Presidency deploy to receive, review, validate, and archive sensitive documents when the Head of State is outside national borders? Public announcements on social media or official websites only reveal the final step in a complex process—one that says nothing about how the document was prepared, transmitted, examined, signed, or preserved.

Mandatory institutional emails under the @prc.cm domain

Every interaction concerning state matters must begin with a secure email address tied to the Presidency’s official domain. Staff should use personalized institutional accounts like [email protected], alongside functional addresses for the General Secretariat, Civil Cabinet, and other departments. Functional accounts such as [email protected] should take priority.

Personal accounts—Gmail, Yahoo, or others—are unsuitable for transmitting draft decrees, confidential memos, appointment files, diplomatic correspondence, or state directives. The issue isn’t just the security features of these platforms but their governance. With personal accounts, the state lacks full control over creation, device access, message retention, recovery, or deactivation after staff departures.

A professional messaging system under @prc.cm would enable:

  • Centralized account management: creation and revocation of staff accounts;
  • Enhanced authentication: enforcement of multi-factor authentication;
  • Document retention: secure storage of official exchanges;
  • Threat detection: identification of suspicious login attempts;
  • Data protection: prevention of automatic forwarding to personal inboxes;
  • Unified security policies: standardized encryption and archiving protocols.

To prevent identity theft and phishing, the system must integrate SPF, DKIM, and DMARC protocols, alongside end-to-end encryption for server communications. Even with a secure institutional address, highly sensitive documents shouldn’t be sent as attachments. Instead, collaborators should be notified that the file is available in a secure presidential platform.

A dedicated presidential document management platform

The Presidency requires a specialized electronic document management system designed for state affairs. Each file should be registered with a unique identifier, author details, confidentiality level, authorized access list, version history, comments, approvals, validation date, and complete access logs.

The Head of State could then view documents from a secure terminal, add notes, request revisions, or approve proposals—without files being duplicated across devices or shared via personal mailboxes. For highly sensitive documents, the system should block local downloads, printing, text copying, or unauthorized transfers.

It should also track who accessed a document, when, from which device, and what changes were made—ensuring every action is documented and tamper-proof.

Electronic signatures with verifiable authenticity

Remote validation of decrees or decisions shouldn’t rely on scanned images of a signature. Instead, a cryptographically signed electronic signature ensures:

  • Signatory identity verification;
  • Document integrity;
  • Timestamped validation;
  • Post-signature alteration detection.

The cryptographic key for high-level signatures should be stored in a hardware security module—not on a standard computer, USB drive, or personal phone. Each use of this key must require direct presidential authentication and generate a time-stamped audit trail. For critical decisions, the process could include multiple layers: presidential approval, technical signature verification, legal review, official registration, and public release.

Zero Trust architecture for remote access

A Virtual Private Network (VPN) secures connections between officials abroad and presidential servers, but it’s not enough. The Presidency should adopt a Zero Trust model, assuming no user, device, or network is inherently trustworthy. Access requests must be verified based on:

  • User identity;
  • Device type;
  • Connection location;
  • Document sensitivity level;
  • Assigned user permissions;
  • Behavioral patterns during the session.

Accessing a presidential file could require a recognized institutional device, a digital certificate, encrypted transmission, a physical security key, and a local biometric check on the device itself.

Exclusively institutional devices for state business

Sensitive documents must never be accessed from personal phones. Members of the Civil Cabinet, General Secretariat, and other relevant departments should use devices and mobile terminals owned and managed by the institution. These should feature:

  • Full-disk encryption;
  • Regular security updates;
  • Restricted app access;
  • Separation from personal use;
  • Remote wipe capability if lost;
  • Automatic lock after inactivity;
  • Prohibition of public Wi-Fi connections.

A centralized device management solution would allow the administration to push updates, block dangerous apps, revoke compromised devices, and remotely erase data in case of theft or breach.

Phishing-resistant authentication protocols

A single password—no matter how complex—is insufficient for accessing presidential documents. Authentication should combine multiple factors:

  • A recognized institutional device;
  • A personal PIN;
  • A physical security key;
  • Optionally, a local biometric check.

While SMS-based one-time codes can add security, they remain vulnerable to certain attacks. For high-risk accounts, physical keys and digital certificates offer superior protection against phishing. Staff should also undergo regular training to recognize fraudulent messages, urgent scams, malicious links, and impersonation attempts targeting senior officials.

WhatsApp: ideal for alerts, not for document exchange

WhatsApp’s end-to-end encryption protects message content during transmission, but that doesn’t make it suitable for official document exchange. Risks remain:

  • Loss or espionage of unsecured devices;
  • Screenshots or unauthorized forwarding;
  • Inadequately protected backups;
  • Use of personal phones by former staff.

WhatsApp lacks the features needed for document classification, access control, version management, electronic signing, or administrative archiving. It can, however, be used to alert collaborators that a file is ready in the secure presidential portal—for example: ‘File PRC/SG/2026/125 is available in your secure workspace for review.’ The document itself should never be attached to the conversation.

The guiding principle: ‘Use WhatsApp to coordinate and alert; the secure presidential platform to transmit, review, decide, sign, and archive.’

Secure government videoconferencing solutions

Remote exchanges between the President and collaborators should occur via a dedicated, government-grade videoconferencing platform. This system must ensure:

  • Encrypted communications;
  • Participant identification;
  • Strict invitation controls;
  • Prohibition of unauthorized recordings;
  • Connection logging;
  • Use of institutional devices only;
  • Data hosting under national control.

Public links, free accounts, and unvetted apps are unsuitable for meetings on defense, diplomacy, appointments, or government arbitrations.

Classifying documents by sensitivity

Not all presidential documents carry the same level of risk. A classification policy could include four tiers:

  • Public: intended for public dissemination;
  • Internal: reserved for government services;
  • Confidential: disclosure could harm public action;
  • Highly sensitive: related to defense, intelligence, diplomacy, or strategic appointments.

Each tier dictates the allowed transmission channel, authorized personnel, permitted devices, printing restrictions, retention periods, and archiving methods. Public documents may be sent via professional messaging, but highly sensitive files must remain accessible only through a highly secured portal.

Comprehensive traceability of every decision

Every consultation, modification, validation, or transmission must be automatically logged. Security logs should include:

  • Who accessed the document;
  • When they accessed it;
  • From which device;
  • What changes were made;
  • Who approved the final version;
  • When it was officially recorded and published.

A dedicated security operations center could detect unusual activity, such as mass downloads, access from unrecognized devices, or unauthorized modifications to official acts. This traceability also aids investigations into leaks, intrusions, or disputes over the authenticity of decisions.

Distinguishing official decisions from social media posts

Presidential Facebook pages and X accounts facilitate rapid public communication, but they’re not the systems used to prepare or validate decisions. Before a decree appears online, it must follow a strict process:

  • Transmission via authorized channels;
  • Authentication of the competent authority;
  • Verification that the final version is unaltered;
  • Timestamped validation;
  • Preservation of the original in official archives.

A visible signature on a shared image doesn’t constitute full digital proof. Security depends on the entire process preceding publication.

Ten priority measures for the Presidency

The Presidency could implement ten critical actions:

  1. Mandate professional email under the @prc.cm domain;
  2. Ban personal Gmail, Yahoo, and similar accounts for state business;
  3. Deploy a presidential electronic document management platform;
  4. Introduce a secure institutional electronic signature system;
  5. Provide exclusively professional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Restrict WhatsApp to alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security operations center;
  10. Train staff regularly on espionage, phishing, and information leaks.

While no public evidence confirms the use of all these measures by Cameroon’s Presidency, they represent the minimum safeguards required for an institution handling remote decisions on finance, diplomacy, security, and state continuity. These concerns—secure document transmission, electronic signatures, data sovereignty, and digital continuity—will be central to E-Gov’A 2026, the E-Government Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, in Yaoundé.

The essence of remote presidential work isn’t merely technical feasibility. The real challenge lies in ensuring that every critical decision leaves an indelible digital footprint: who posted what, approved what, when, through which channel, and with what security guarantees?