The ability to review files, coordinate with teams, issue directives, and validate administrative acts from abroad is now within reach. Yet when it comes to the President of the Republic, remote governance cannot rely on ordinary digital tools. It requires systems capable of ensuring information confidentiality, verifying the decision-maker’s identity, safeguarding document integrity, and tracking every instruction.
President Paul Biya’s administration continues to operate beyond national borders, as confirmed by the Minister of Higher Education, Jacques Fame Ndongo, who dismissed rumors of a vacancy at the helm of the State. He emphasized that the Head of State remains actively engaged, whether in person or through established electronic channels. This raises a critical question: what secure digital infrastructure should a modern presidential office deploy to receive, process, validate, and archive sensitive documents when the President is outside Cameroon?
Institutional email systems under the @prc.cm domain
The first line of defense lies in using official email addresses tied to the Presidency’s domain. Every advisor and civil servant should have a dedicated institutional account—such as [email protected]—alongside functional addresses for the General Secretariat, Civil Cabinet, and other departments. Personal accounts like Gmail or Yahoo have no place in handling state affairs, whether for decree drafts, confidential memos, diplomatic correspondence, or executive orders.
The risks extend beyond technical vulnerabilities. Personal accounts fall outside state control: authorities cannot manage their creation, linked devices, message retention, recovery protocols, or deactivation upon staff departures. An institutional system under @prc.cm would enable:
- Controlled account creation and revocation for staff;
- Mandatory multi-factor authentication;
- Secure archiving of all official exchanges;
- Detection of suspicious login attempts;
- Blocking automatic forwarding to personal inboxes;
- Uniform security policies and retention schedules.
To prevent identity theft and phishing, the system must implement SPF, DKIM, and DMARC protocols, alongside end-to-end encryption between servers. Even with a secured institutional address, highly sensitive documents should never be attached directly. Instead, the system should notify recipients that a file is available in the presidential secure platform.
A dedicated presidential document management platform
A specialized electronic document management system (EDMS) is essential for handling state affairs. Each file would be assigned a unique identifier, author details, confidentiality level, authorized viewer list, version history, comments, approvals, timestamps, and a complete access log. The President could access documents from a secure terminal, add notes, request revisions, or approve proposals without files being copied across multiple devices or sent to personal mailboxes.
For the most sensitive materials—defense briefs, intelligence reports, diplomatic cables—downloading, printing, text copying, or unauthorized sharing must be disabled. The platform should also log who viewed a document, when, from which device, and what changes were made.
Electronic signatures that stand up to scrutiny
Remote validation of decrees or decisions must move beyond scanned images of a signature. Digital signatures based on cryptographic certificates provide verifiable proof of:
- Signatory identity;
- Document integrity;
- Exact date and time of validation;
- Lack of post-signature alterations.
The cryptographic key used for critical acts should be stored in a tamper-proof hardware module—not on a standard computer, USB drive, or personal phone. Every use of this key requires direct presidential authentication and generates a time-stamped audit trail. For major decisions, the process could include layered checks: presidential approval, technical signature verification, legal review, official recording, and public release.
A Zero Trust framework for remote access
A virtual private network (VPN) secures connections between officials abroad and presidential servers, but it cannot be the sole safeguard. A Zero Trust architecture operates on the principle that no user, device, or network should be inherently trusted. Access requests are evaluated based on:
- User identity;
- Device authenticity;
- Geographic location of the connection;
- Document sensitivity level;
- User permissions;
- Behavioral patterns during the session.
Accessing a presidential file could require an official institutional device, a digital certificate, encrypted connectivity, a physical security key, and a local biometric scan on the terminal. This multilayered approach ensures that even if one layer is compromised, unauthorized access remains blocked.
Exclusively institutional devices for all staff
No presidential documents should ever be accessed via personal phones or computers. Civil Cabinet members, General Secretariat staff, and other officials handling sensitive files must use equipment owned and administered by the Presidency. These devices should be:
- Fully encrypted at all times;
- Subject to routine security updates;
- Limited to approved applications only;
- Segregated from personal use;
- Remotely wipeable in case of loss;
- Automatically locked after brief inactivity;
- Banned from unsecured public Wi-Fi networks.
A centralized endpoint management system allows the administration to push updates, block dangerous apps, revoke devices, and wipe data remotely in the event of theft or compromise.
Phishing-resistant authentication protocols
A complex password alone is insufficient for accessing presidential files. Authentication should combine multiple factors:
- An institutional device;
- A personal PIN or password;
- A physical security key;
- Optional local biometric verification.
SMS-based one-time codes add a layer of protection but remain vulnerable. For the highest-risk accounts, physical keys and digital certificates offer superior resistance to phishing attacks. Staff must also undergo regular training to recognize fraudulent messages, urgent scams, malicious links, and attempts to impersonate superiors.
WhatsApp: useful for alerts, not for document transmission
While widely used across Cameroon—including within administrations—WhatsApp’s end-to-end encryption protects message content in transit. However, this does not qualify it as an official platform for presidential document handling. A file shared via WhatsApp remains exposed through lost phones, screen captures, unauthorized forwarding, linked devices, insecure backups, or personal devices of former staff. WhatsApp also lacks the functionality to classify files, manage access rights, track versions, validate acts, or ensure regulatory archiving.
The app can still play a role in coordination: alerting that a file is ready in the secure platform, confirming meetings, or signaling urgent actions. For example, a message could read: “File PRC/SG/2026/125 is available in your secure workspace for review.” The document itself must never be attached to the chat.
In short: Use WhatsApp for alerts and coordination; rely on the presidential secure platform for transmission, review, decision-making, signing, and archiving.
Secure government video conferencing solutions
Remote discussions between the President and advisors should occur via dedicated, government-grade videoconferencing platforms. These systems must provide:
- Encrypted communication channels;
- Verified participant identities;
- Strict invitation controls;
- Prohibition of unauthorized recordings;
- Retention of connection logs;
- Exclusive use of institutional devices;
- Full data hosting oversight.
Public links, free accounts, and unvetted applications have no place in meetings involving defense, diplomacy, appointments, or government arbitration.
Classifying documents by sensitivity level
Not all presidential documents carry the same risk. A classification policy could define four categories:
- Public: intended for public dissemination;
- Internal: working documents for government services only;
- Confidential: disclosure could harm public action;
- Highly sensitive: relates to defense, intelligence, diplomacy, strategic appointments, or major arbitrations.
Each level dictates transmission channels, authorized personnel, permissible devices, printing rights, retention periods, and archival procedures. A public document may be sent via institutional email, while a highly sensitive file must remain accessible only within a tightly controlled platform.
Complete traceability for every decision
Every consultation, modification, validation, or transmission must be automatically logged. The security journal should capture:
- Who accessed the document;
- When the access occurred;
- Which device was used;
- What changes were made;
- Who approved the final version;
- When the document was officially recorded and published.
A dedicated security operations center can detect unusual logins, bulk downloads, access from unrecognized devices, or unauthorized modifications to official acts. This traceability also enables reconstruction of events in the event of a leak, intrusion, or dispute over the authenticity of a decision.
Distinguishing official decisions from social media posts
The Presidency’s Facebook page and X account serve to inform the public quickly. They are not—and should never be confused with—the systems used to prepare and validate decisions. Before a decree appears on social media, it must follow a secure process:
- The document traveled through authorized channels;
- The authority was authenticated;
- The final version remained unaltered;
- The validation was time-stamped;
- The original is preserved in official archives.
A visible signature on an online image does not constitute full digital proof. Security rests on the complete process that preceded publication.
Ten priority measures for the Presidency
To modernize remote governance, the Presidency could implement ten critical actions:
- Mandate institutional email under the @prc.cm domain;
- Ban personal Gmail, Yahoo, and similar accounts for state business;
- Deploy a presidential electronic document management platform;
- Introduce a secure institutional electronic signature system;
- Provide exclusively professional phones and computers to staff;
- Enforce phishing-resistant multi-factor authentication;
- Restrict WhatsApp to alerts and coordination;
- Classify documents by sensitivity level;
- Centralize access logs in a security operations center;
- Conduct regular training on espionage, phishing, and data leaks risks.
The current use of such measures by Cameroon’s Presidency remains unverified in public records. Yet these represent the minimum safeguards a state institution must adopt when handling remotely sensitive files that impact finances, diplomacy, security, and the continuity of governance. At a time when artificial intelligence, cyberattacks, and digital forgery are rising threats, the State can no longer afford informal digital practices. It must deploy modern tools and procedures to ensure that every major decision leaves a verifiable trail: who posted what, approved what, when, through which channel, and with what security guarantees?



