How Cameroon’s presidency can ensure secure remote work for president paul biya

How Cameroon’s presidency can ensure secure remote work for President Paul Biya

Paul Biya

Managing state affairs remotely—consulting files, exchanging with collaborators, issuing directives, or validating administrative acts—has become technically feasible. However, for a Head of State like President Paul Biya, remote governance cannot rely on ordinary digital tools. It requires systems capable of guaranteeing the confidentiality of information, authenticity of the decision-maker, integrity of documents, and traceability of every instruction.

This debate gained momentum following a statement by Cameroon’s Minister of State for Higher Education, Professor Jacques Fame Ndongo. In a communiqué refuting claims of a “vacancy” at the state’s helm, he asserted that President Biya continues to oversee files and issue directives, “in person” or via “electronic means known to all.” While this addresses political discourse, it raises a critical question: What secure digital tools should a modern presidency use to receive, review, approve, and archive sensitive documents when the Head of State is abroad?

Publishing a decree on social media or a presidency website is merely the final step in public communication. It reveals nothing about how the document was prepared, transmitted, reviewed, signed, recorded, or preserved.

Professional email under the @prc.cm domain

The first priority is the systematic use of institutional email addresses linked to the official domain of the Presidency of the Republic. Collaborators must have personalized addresses—such as [email protected]—as well as functional addresses for the General Secretariat, Civil Cabinet, and other departments. For example, [email protected] should be the primary channel for official communications.

Personal accounts—Gmail, Yahoo, or similar—must never be used to transmit draft decrees, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The issue extends beyond technical security capabilities. Personal accounts fall partially outside state control: their creation, connected devices, message retention, recovery, or deactivation upon a collaborator’s departure are not fully managed by the administration.

A professional messaging system under the @prc.cm domain would enable:

  • Creation and revocation of collaborator accounts;
  • Enforcement of multi-factor authentication;
  • Preservation of official exchanges;
  • Detection of suspicious connections;
  • Blocking of automatic forwarding to personal mailboxes;
  • Implementation of a unified security and archiving policy.

This system must also prevent identity theft and phishing via mechanisms like SPF, DKIM, and DMARC. Communications between servers should be encrypted. Even with a secure institutional address, sensitive files should not be sent as simple attachments. Instead, the recipient should be notified that the document is available in a secure presidential platform.

A presidential platform for document management

The Presidency must have an electronic document management system tailored to state affairs. Each file should be recorded with:

  • A unique reference;
  • The author’s identity;
  • Its confidentiality level;
  • Authorized personnel for access;
  • Document versions;
  • Comments and approvals;
  • Validation date;
  • A complete access history.

This allows the Head of State to consult documents from a secure terminal, add observations, request modifications, or approve proposals—without the file being copied across multiple devices or sent to personal mailboxes.

For highly sensitive files, the platform should prevent local downloads, printing, text copying, or unauthorized transfers. It should also log who accessed the document, when, from which device, and what changes were made.

Verifiable electronic presidential signatures

Remote validation of decrees or decisions should not rely on scanned images of handwritten signatures. Instead, digital signatures based on cryptographic certificates must be used to verify:

  • The signatory’s identity;
  • The document’s integrity;
  • The date and time of validation;
  • The absence of post-signature modifications.

The cryptographic key used for signing critical documents must be stored in a highly secure hardware module—not on a regular computer, USB drive, or personal phone. Each use of this key should require direct authentication by the Head of State and generate a time-stamped log.

For major decisions, the process could include multiple checks: presidential validation, technical signature verification, legal review, official registration, and then publication.

Zero Trust architecture for remote access

A Virtual Private Network (VPN) can secure connections between traveling officials and presidential servers, but it should not be the sole safeguard. Adopting a Zero Trust architecture—where no user, device, or network is trusted by default—is essential. Each access request must be verified based on:

  • User identity;
  • Device used;
  • Connection location;
  • Document sensitivity level;
  • User’s assigned permissions;
  • Observed behavior during the session.

Accessing presidential files could require a recognized institutional computer, a digital certificate, an encrypted connection, a physical security key, and a local biometric verification on the device.

Exclusively institutional phones and computers

Presidential files must never be accessed from personal devices of collaborators. Members of the Civil Cabinet, General Secretariat, and departments handling such documents should use equipment and mobile terminals owned and managed by the institution. These devices must be:

  • Fully encrypted;
  • Regularly updated;
  • Limited to authorized applications;
  • Segregated from personal use;
  • Remotely erasable in case of loss;
  • Automatically locked after inactivity;
  • Restricted from connecting to unsecured public Wi-Fi networks.

A centralized terminal management solution would enable the administration to install updates, block dangerous applications, revoke devices, and remotely delete data in case of theft or compromise.

Phishing-resistant authentication

A password, even complex, should never suffice for accessing Presidency files. Authentication should combine:

  • An institutional device;
  • A personal code;
  • A physical security key;
  • Possibly local biometric verification.

SMS codes can enhance security but remain vulnerable to attacks. For highly sensitive accounts, physical keys and digital certificates offer superior resistance to phishing attempts.

Collaborators should also be regularly trained to recognize fake messages, fraudulent urgent requests, malicious links, and attempts to impersonate superiors.

WhatsApp: useful for alerts, not for file transfers

WhatsApp is widely used in Cameroon, including in administrations, thanks to its end-to-end encryption. However, this does not make it an official platform for managing presidential documents.

A file shared via WhatsApp remains exposed if:

  • The phone is lost or compromised;
  • A screenshot is taken;
  • It is forwarded without authorization;
  • It is backed up insecurely;
  • It remains on a collaborator’s personal device after they leave office.

WhatsApp alone cannot provide mechanisms for document classification, access management, version control, validation recording, electronic signing, or administrative archiving. The app could be used to announce that a file is available, confirm meetings, report emergencies, or coordinate travel. For example: “File referenced PRC/SG/2026/125 is available in your secure space for review.” The actual document should never be attached to the conversation.

The rule is clear: Use WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision-making, signing, and archiving.

Secure government videoconferencing solutions

Remote exchanges between the President and collaborators should also use dedicated government videoconferencing platforms. Such solutions must ensure:

  • Encrypted communications;
  • Participant identification;
  • Strict invitation controls;
  • Prohibition of unauthorized recordings;
  • Connection log retention;
  • Exclusive use of institutional terminals;
  • Data hosting oversight.

Public links, free accounts, and unvetted applications should never be used for meetings concerning defense, diplomacy, appointments, or government arbitrations.

Document classification by sensitivity level

Not all Presidency documents carry the same risk. A classification policy could define four categories:

  • Public: Documents intended for dissemination;
  • Internal: Working documents restricted to state services;
  • Confidential: Documents whose disclosure could harm public action;
  • Highly sensitive: Documents related to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each level determines the authorized transmission channel, authorized personnel, usable devices, printing capabilities, retention duration, and archiving methods. A public document could be sent via professional email, while a highly sensitive file must remain accessible only through a tightly controlled platform.

Maintaining a complete trace of every decision

Every consultation, modification, validation, or transmission must be automatically logged. The security log should detail:

  • Who accessed the document;
  • When they accessed it;
  • From which device;
  • What changes were made;
  • Who approved the final version;
  • When and by whom it was recorded and published.

A security operations center could detect unusual connections, mass document downloads, access attempts from unrecognized equipment, or abnormal modifications to official acts. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over the authenticity of a decision.

Distinguishing official decisions from social media posts

Presidency Facebook pages and X accounts enable rapid public communication but must not be confused with the systems used to prepare and validate decisions.

Before a decree is published on social media, it must follow a process:

  • Transmitted through authorized channels;
  • Authenticated by the competent authority;
  • Verified to ensure no alterations;
  • Time-stamped upon validation;
  • Preserved in official archives.

A visible signature on an online image alone does not constitute full digital proof. Security lies in the complete process preceding publication.

Ten essential measures for the Presidency

The Presidency of the Republic could implement ten priority actions:

  1. Mandate professional email under the @prc.cm domain;
  2. Ban personal accounts (Gmail, Yahoo, etc.) for state affairs;
  3. Deploy a presidential electronic document management platform;
  4. Introduce a secure institutional electronic signature system;
  5. Provide exclusively professional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Reserve WhatsApp for alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security operations center;
  10. Regularly train collaborators on espionage, phishing, and information leak risks.

While no public information confirms the use of these measures by the Cameroonian Presidency, they represent the minimum safeguards required for an institution handling remote files that impact finance, diplomacy, security, and state continuity. Ensuring secure document transmission, electronic signatures, data sovereignty, and digital continuity will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14-16, 2026, in Yaoundé. The event, held under the theme “Artificial intelligence and e-governance: building efficient public services in a cashless and paperless Africa,” will convene policymakers, development organizations, public institutions, businesses, and experts to explore these challenges.

The question is not whether a president can work from Geneva, Paris, New York, or elsewhere. The real challenge is whether the tools used can authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in their name.

Modern tools and traceability: the foundation of trust

Remote presidential work is not an insurmountable technological challenge. The true obstacle lies in the trust placed in tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must use modern tools to ensure that every critical decision leaves a trace: who posted what, approved what, when, through which channel, and with what security guarantees?