Cameroon: secure digital tools for president Paul Biya’s remote work

Cameroon: secure digital tools for president Paul Biya’s remote work

Paul Biya

Accessing files abroad, coordinating with teams, or approving administrative acts remotely is technically feasible today. However, when it comes to the Head of State, remote work cannot rely on standard digital tools. Instead, it requires systems that guarantee information confidentiality, decision-maker identity verification, document integrity, and traceability of every instruction.

Minister of Higher Education Jacques Fame Ndongo recently addressed this issue, asserting that President Paul Biya continues to oversee files and issue directives—either in person or via “widely known electronic means.” This statement raises a critical question: what digital tools should a modern presidential administration use to receive, review, approve, and securely archive sensitive documents when the Head of State is outside national territory?

Posting a decree on social media merely represents the final step in public communication. It reveals nothing about how the document was prepared, transmitted, reviewed, signed, registered, or preserved.

Professional email under the @prc.cm domain

The first priority must be the systematic use of institutional email addresses linked to the official Presidential domain. Close collaborators should have personalized accounts, such as [email protected], along with functional addresses for the General Secretariat, Civil Cabinet, and other departments. For instance, [email protected] should be the primary channel for official correspondence.

Personal accounts like Gmail or Yahoo are unsuitable for transmitting draft decrees, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The issue isn’t just about the technical security capabilities of these platforms but their governance. A personal email account falls partially outside administrative control, making it difficult to manage creation, device access, message retention, recovery, or deactivation after a staff member leaves.

A professional email system under @prc.cm would enable:

  • Creating and revoking staff accounts;
  • Enforcing multi-factor authentication;
  • Storing official exchanges;
  • Detecting suspicious logins;
  • Blocking automatic transfers to personal inboxes;
  • Applying unified security and archiving policies.

This system must also guard against identity theft and phishing using SPF, DKIM, and DMARC protocols while enforcing server-to-server encryption. Even a well-protected institutional address shouldn’t be used to send highly sensitive documents directly. Instead, it could notify recipients that a file is available in a secure presidential platform.

A presidential platform for document management

The Republic’s Presidency requires a specialized electronic document management platform for state affairs. Each file should be registered with:

  • A unique reference;
  • The author’s identity;
  • Confidentiality level;
  • Authorized viewers;
  • Document versions;
  • Comments and arbitrations;
  • Validation date;
  • A complete access history.

This would allow the Head of State to consult documents from a secure terminal, add notes, request modifications, or approve proposals without files being copied across devices or sent to personal emails. For highly sensitive files, the platform should prevent local downloads, printing, text copying, or unauthorized transfers. It should also track who accessed documents, when, from which device, and what changes were made.

A verifiable electronic presidential signature

Remote validation of decrees or decisions shouldn’t rely on scanned images of the President’s signature. Instead, an electronic signature using digital certificates would verify:

  • The signatory’s identity;
  • Document integrity;
  • Validation date and time;
  • Absence of post-signature modifications.

The cryptographic key for signing critical documents must be stored in a highly secure hardware module—not on ordinary computers, USB drives, or personal phones. Every use of this key should require direct presidential authentication and generate a timestamped log.

For major decisions, the process could include multiple verification steps: presidential validation, technical signature verification, legal review, official registration, and then publication.

A Zero Trust remote access framework

A virtual private network (VPN) can secure connections between traveling officials and presidential servers, but it shouldn’t be the sole safeguard. The Presidency could adopt a Zero Trust architecture, assuming no user, device, or network is inherently trustworthy. Each access request would be verified based on:

  • User identity;
  • Device used;
  • Connection location;
  • Document sensitivity level;
  • Assigned user permissions;
  • Observed connection behavior.

Accessing presidential files might require an approved institutional computer, a digital certificate, encrypted connection, physical security key, and local biometric verification on the device.

Exclusively institutional phones and computers

Presidential files shouldn’t be accessed from staff members’ personal devices. Civil Cabinet, General Secretariat, and relevant department members should use institution-owned and administered equipment that is:

  • Fully encrypted;
  • Regularly updated;
  • Limited to authorized applications;
  • Separated from personal use;
  • Remotely erasable if lost;
  • Automatically locked after inactivity;
  • Restricted from connecting to unsecured public Wi-Fi networks.

A centralized terminal management solution would allow administration to install updates, block dangerous applications, revoke devices, and remotely delete data in case of theft or compromise.

Anti-phishing authentication

A password, even complex, is insufficient for accessing Presidential files. Authentication should combine:

  • An approved institutional device;
  • A personal code;
  • A physical security key;
  • Potential local biometric verification.

SMS codes can enhance security but remain vulnerable to certain attacks. For highly sensitive accounts, physical keys and digital certificates offer better resistance to phishing attempts. Staff should also receive regular training to recognize fraudulent messages, urgent scams, malicious links, and attempts to impersonate superiors.

WhatsApp for alerts, not document transfers

WhatsApp is widely used in Cameroon, including within administrations, thanks to its end-to-end encryption. However, this protection doesn’t make it an official platform for presidential document management.

A file sent via WhatsApp remains exposed if:

  • The phone is lost or compromised;
  • A screenshot is taken;
  • It’s transferred without authorization;
  • It’s backed up insecurely;
  • It’s accessed from another linked device;
  • It’s on a former staff member’s personal phone.

WhatsApp alone also lacks mechanisms for file classification, permission management, version control, validation recording, electronic signing, or administrative archiving. It could be used to announce a file’s availability, confirm meetings, signal emergencies, or coordinate travel. For example: “File reference PRC/SG/2026/125 is available in your secure workspace for review.” The document itself shouldn’t be attached. The rule is simple: WhatsApp for alerts, presidential platform for transmission, review, decision, signing, and archiving.

Secure government videoconferencing solutions

Remote exchanges between the President and collaborators should use dedicated government videoconferencing platforms that enable:

  • Encrypted communications;
  • Participant identification;
  • Strict invitation control;
  • Prohibition of unauthorized recordings;
  • Connection log retention;
  • Exclusive use of institutional terminals;
  • Data hosting oversight.

Public links, free accounts, and unvalidated applications shouldn’t be used for defense, diplomacy, appointments, or government arbitration meetings.

Document sensitivity classification

Not all Presidential documents carry the same risk level. A classification policy could include four categories:

  • Public: intended for dissemination;
  • Internal: working documents for state services;
  • Confidential: potential public harm if disclosed;
  • Highly sensitive: related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each level determines the authorized transmission channel, permitted viewers, usable devices, printing capabilities, retention duration, and archiving methods. A public document could be sent via professional email, while a highly sensitive file should only be accessible through a strongly compartmentalized platform.

Complete traceability for every decision

Every consultation, modification, validation, or transmission should be automatically recorded, with security logs specifying:

  • Who accessed the document;
  • When it was accessed;
  • From which device;
  • What changes were made;
  • Who validated the final version;
  • When and by whom it was registered and published.

A security supervision center could detect unusual connections, mass document downloads, attempts to access from unrecognized devices, or abnormal modifications to official acts. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over decision authenticity.

Distinguishing official decisions from social media posts

The Presidency’s Facebook and X accounts enable rapid public communication but shouldn’t be confused with systems used to prepare and validate decisions. Before a decree is published online, it must follow a strict process:

  • The document was transmitted through an authorized channel;
  • The competent authority was authenticated;
  • The final version wasn’t altered;
  • The validation was timestamped;
  • The original is preserved in official archives.

A visible signature on an online image doesn’t constitute complete digital proof. Security relies on the entire preceding process.

Ten priority measures for the Presidency

The Republic’s Presidency could implement ten critical actions:

  1. Mandate professional email under the @prc.cm domain;
  2. Ban personal Gmail, Yahoo, and similar accounts for state affairs;
  3. Deploy a presidential electronic document management platform;
  4. Introduce a secure institutional electronic signature system;
  5. Provide exclusively professional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Reserve WhatsApp for alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a supervision center;
  10. Train staff regularly on espionage, phishing, and information leak risks.

No public information confirms whether Cameroon’s Presidency currently uses all these systems. However, they represent the minimum safeguards a state institution should adopt when handling remotely sensitive files affecting finances, diplomacy, security, and national continuity.

These challenges of secure document transmission, electronic signatures, data sovereignty, and digital state continuity will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, at the Yaoundé Congress Palace. The event, organized under the high patronage of the Ministry of Posts and Telecommunications, will focus on the theme: “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa.”

The question isn’t whether a president can work from Geneva, Paris, New York, or elsewhere. The essential challenge is determining whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in their name.

Modern tools and traceability

Remote presidential work isn’t an insurmountable technological challenge. The real hurdle lies in trusting the tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must adopt modern tools, methods, and approaches to ensure every critical decision leaves a trace: who posted what, validated what, when, through which channel, and with what security guarantees?