Mali Voice

Your English-language guide to Mali's news landscape — clear, credible and up to date.

Mali Voice

Your English-language guide to Mali's news landscape — clear, credible and up to date.

Secure digital tools for presidential remote work in Cameroon

Secure digital tools for presidential remote work in Cameroon

President Paul Biya

The ability to review files, exchange with collaborators, issue instructions, or approve administrative acts remotely is now technically feasible. However, when it comes to the Head of State, remote work continuity cannot rely on ordinary digital tools. It requires systems capable of ensuring information confidentiality, verifying the decision-maker’s identity, maintaining document integrity, and tracking every instruction.

The debate on remote governance was reignited following a statement by the Minister of State for Higher Education, Professor Jacques Fame Ndongo. In a communiqué denying claims of “vacancy” at the helm of the State, he asserted that President Paul Biya continues to monitor files and issue directives, either “in person” or through “electronic means known to all.”

This assertion raises a critical question: What digital tools should a modern Presidency use to receive, review, approve, and archive sensitive documents when the Head of State is abroad?

Institutional email addresses under the @prc.cm domain

The first requirement is the systematic use of official email addresses linked to the Presidency’s domain. Collaborators must have personalized addresses, such as [email protected], as well as functional addresses reserved for the Secretary-General, Civil Cabinet, and other services—like [email protected]—which should be prioritized.

Personal accounts (Gmail, Yahoo, etc.) must never be used for transmitting draft decrees, confidential memos, appointment files, diplomatic correspondence, or state-engaging instructions. The issue isn’t just the security capabilities of these platforms but their governance. Personal accounts fall partially outside state control: their creation, connected devices, message retention, recovery, or deactivation after an official’s departure aren’t always manageable by the administration.

A professional messaging system under @prc.cm would enable:

  • Creating and revoking collaborator accounts;
  • Enforcing strong authentication;
  • Preserving official exchanges;
  • Detecting suspicious logins;
  • Preventing automatic transfers to personal inboxes;
  • Implementing uniform security and archiving policies.

This system must be protected against identity theft and phishing using mechanisms like SPF, DKIM, and DMARC, with encrypted server-to-server communications. However, even a well-secured institutional address shouldn’t be used to send highly sensitive documents directly. Instead, it should notify the recipient that a file is available in a secure presidential platform.

A presidential platform for document management

The Presidency should have an electronic document management platform tailored for state affairs. Each file could be registered with:

  • A unique reference;
  • The author’s identity;
  • Confidentiality level;
  • Authorized viewers;
  • Document versions;
  • Comments and arbitrations;
  • Validation date;
  • Complete access history.

This would allow the Head of State to consult a document from a secure terminal, add observations, request modifications, or approve proposals without the file being copied across multiple devices or sent to personal mailboxes. For highly sensitive files, the platform should prevent local downloads, printing, text copying, or unauthorized transfers.

Verifiable electronic presidential signatures

Remote validation of decrees or decisions shouldn’t rely on a scanned image of the President’s signature. An electronic signature based on digital certificates ensures:

  • Signatory identity verification;
  • Document integrity;
  • Validation date and time;
  • Post-signature tamper-proofing.

The cryptographic key for signing critical acts must be stored in a highly secure hardware module—not on a regular computer, USB drive, or personal phone. Its use should require direct presidential authentication and generate a timestamped trace. For major decisions, the process could include multiple checks: presidential validation, technical signature verification, legal review, official registration, and publication.

Zero Trust-based remote access

A VPN can secure connections between a traveling official and presidential servers but shouldn’t be the sole safeguard. The Presidency could adopt a Zero Trust architecture, assuming no user, device, or network is trustworthy by default. Each access request would be verified based on:

  • User identity;
  • Device used;
  • Connection location;
  • Document sensitivity level;
  • Assigned user rights;
  • Observed connection behavior.

Access to presidential files could require an institutional computer, digital certificate, encrypted connection, physical security key, and local biometric verification on the device.

Exclusively institutional phones and computers

Presidential files must never be accessed from collaborators’ personal phones. Members of the Civil Cabinet, Secretary-General, and relevant services should use institution-owned, centrally managed devices that are:

  • Fully encrypted;
  • Regularly updated;
  • Limited to authorized applications;
  • Separated from personal use;
  • Remotely erasable if lost;
  • Automatically locked after inactivity;
  • Prohibited from connecting to unsecured public Wi-Fi.

A centralized terminal management solution would allow the administration to install updates, block dangerous apps, revoke devices, and remotely wipe data in case of theft or compromise.

Phishing-resistant authentication

A password—even complex—should never suffice for accessing Presidency files. Authentication should combine:

  • An institutional device;
  • A personal code;
  • A physical security key;
  • Possibly local biometric verification.

SMS codes can enhance security but remain vulnerable to certain attacks. For sensitive accounts, physical keys and digital certificates offer better resistance to phishing. Collaborators should also be trained regularly to recognize fake messages, fraudulent urgent requests, malicious links, and attempts to impersonate superiors.

WhatsApp: useful for alerts, not for file transfers

WhatsApp is widely used in Cameroon, including in administrations, thanks to its end-to-end encryption. However, this doesn’t make it an official platform for presidential document management. A file sent via WhatsApp remains exposed through:

  • Lost or hacked phones;
  • Screenshots;
  • Unauthorized transfers;
  • Linked devices;
  • Poorly protected backups;
  • Personal phones of former collaborators.

WhatsApp also lacks mechanisms for file classification, access management, version control, validation recording, electronic signing, or administrative archiving. It could, however, be used to announce that a file is available in a secure space or coordinate urgent matters. For example: “The file referenced PRC/SG/2026/125 is available in your secure space for review.” The document itself should never be attached to the conversation.

The rule is simple: Use WhatsApp for alerts and coordination; the secure presidential platform for transmission, review, decision-making, signing, and archiving.

Secure government videoconferencing solutions

Remote exchanges between the President and collaborators could also use dedicated secure government videoconferencing platforms. These should enable:

  • Encrypted communications;
  • Participant identification;
  • Strict invitation control;
  • Prohibition of unauthorized recordings;
  • Connection log retention;
  • Exclusive use of institutional terminals;
  • Data hosting control.

Public links, free accounts, and unvetted apps should never be used for meetings on defense, diplomacy, appointments, or government arbitrations.

Classifying documents by sensitivity

Not all Presidency documents carry the same risk. A classification policy could distinguish four categories:

  • Public: For dissemination;
  • Internal: Working documents for state services;
  • Confidential: Disclosure could harm public action;
  • Highly sensitive: Defense, intelligence, diplomacy, strategic appointments, or major arbitrations.

Each level determines the authorized transmission channel, authorized personnel, usable devices, printing permissions, retention duration, and archiving methods. A public document could be sent via professional email, while a highly sensitive file should only be accessible through a highly segmented platform.

Comprehensive traceability for every decision

Every consultation, modification, validation, or transmission should be automatically logged. The security journal should detail:

  • Who accessed the document;
  • When they accessed it;
  • From which device;
  • What modifications were made;
  • Who approved the final version;
  • When it was recorded and published, and by whom.

A security operations center could detect unusual logins, massive document downloads, access from unrecognized equipment, or abnormal modifications to official acts. This traceability would also help reconstruct events in case of leaks, intrusions, or disputes over a decision’s authenticity.

Distinguishing official decisions from social media posts

Presidency Facebook pages and X accounts allow rapid public communication but aren’t the systems used to prepare and validate decisions. Before a decree is published on social media, it must follow a process:

  • The document was transmitted through an authorized channel;
  • The competent authority was authenticated;
  • The final version wasn’t altered;
  • The validation was timestamped;
  • The original is preserved in official archives.

A visible signature on an online image isn’t sufficient proof. Security relies on the complete process preceding publication.

Ten priority measures for the Presidency

The Republic Presidency could implement ten priority actions:

  1. Make professional messaging under @prc.cm mandatory;
  2. Ban personal Gmail, Yahoo, and similar accounts for state affairs;
  3. Deploy a presidential electronic document management platform;
  4. Introduce secure institutional electronic signatures;
  5. Provide exclusively professional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Restrict WhatsApp to alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security operations center;
  10. Train collaborators regularly on espionage, phishing, and information leaks.

While no public information confirms the current use of all these measures by the Cameroonian Presidency, they represent the minimum security standards a state institution handling remote sensitive files should adopt. These challenges—secure document transmission, electronic signatures, data sovereignty, and digital state continuity—will be central to E-Gov’A 2026 – E-Gov Africa Summit, Expo & Awards, scheduled for October 14–16, 2026, in Yaoundé, under the theme: “Artificial intelligence and e-governance: building efficient public services in a cashless, paperless Africa.”

The question isn’t whether a president can work from Geneva, Paris, New York, or elsewhere. The essential challenge is determining whether the tools used authenticate decisions, protect state secrets, trace instructions, and ensure no one can alter, divert, or fabricate an act in the President’s name.

Modern tools and traceability

Remote presidential work isn’t an insurmountable technological problem. The real challenge lies in trusting the tools and procedures. In an era of artificial intelligence, cyberattacks, and digital forgeries, the state can no longer rely on informal digital methods. It must leverage modern tools so that every critical decision leaves a trace: who posted what, approved what, when, through which channel, and with what security guarantees?

Secure digital tools for presidential remote work in Cameroon
Scroll to top