Secure digital tools for Cameroun’s president working remotely

Secure digital tools for Cameroun’s president working remotely

The ability to consult files abroad, exchange with collaborators, issue instructions or approve administrative acts is now technically feasible. However, when it comes to the Head of State, remote work cannot rely on ordinary digital tools. It requires systems capable of guaranteeing information confidentiality, decision-maker identity verification, document integrity and traceability of every instruction.

The debate around remote governance was reignited following a statement by Cameroon’s Minister of State for Higher Education, Professor Jacques Fame Ndongo. In a communiqué denying any “vacancy” at the highest level of the state, he affirmed that President Paul Biya continues to oversee files and issue directives, “in person” or through “electronic means known to all.”

This declaration raises a critical question: which digital tools should a modern presidential administration use to receive, review, approve and archive sensitive documents when the Head of State is outside national territory?

Publishing a decree on Facebook, X or the official presidency website represents only the final step in public communication. It doesn’t reveal the process through which the document was prepared, transmitted, reviewed, signed, registered and preserved.

Professional email under @prc.cm domain

The first requirement should be the systematic use of institutional email addresses linked to the official Presidency domain. Collaborators must have personalized addresses like [email protected], as well as functional addresses reserved for the General Secretariat, Civil Cabinet and other services. Addresses like [email protected] should take priority.

Personal accounts such as Gmail or Yahoo should never be used to transmit draft decrees, confidential memos, appointment files, diplomatic correspondence or state-engaging instructions. The issue isn’t just about the technical security capabilities of these services, but primarily about governance. Personal addresses partially escape administrative control: the state doesn’t always control their creation, connected devices, message storage, recovery or deactivation after a staff member leaves.

A professional messaging system under @prc.cm would enable:

  • Creating and revoking collaborator accounts;
  • Implementing strong authentication;
  • Preserving official exchanges;
  • Detecting suspicious connections;
  • Preventing automatic transfers to personal inboxes;
  • Applying unified security and archiving policies.

This messaging system should be protected against identity theft and phishing through mechanisms like SPF, DKIM and DMARC, with encrypted server-to-server communications. Even with well-protected institutional addresses, they shouldn’t be used to send highly sensitive documents as simple email attachments. Instead, they should notify recipients that a file is available in a secure presidential platform.

A presidential platform for document management

The Republic’s Presidency should have an electronic document management platform specifically designed for state affairs. Each file could be registered with:

  • A unique reference;
  • The author’s identity;
  • Its confidentiality level;
  • Authorized access personnel;
  • Document version history;
  • Comments and arbitrations;
  • Validation date;
  • Complete access history.

The Head of State could consult documents from a secure terminal, add observations, request modifications or approve proposals without files being copied across multiple devices or sent to personal email inboxes. For highly sensitive files, the platform should prevent local downloads, printing, text copying or unauthorized transfers.

A verifiable presidential electronic signature

Remote validation of decrees or decisions shouldn’t rely on simple digital scans of the president’s signature. An electronic signature based on digital certificates would verify:

  • The signatory’s identity;
  • Document integrity;
  • Validation date and time;
  • Absence of post-signature modifications.

The cryptographic key used for signing critical documents should be stored in a highly secure hardware module, never on ordinary computers, USB drives or personal phones. Any use of this key should require direct presidential authentication and generate a timestamped record.

Zero Trust-based remote access

While a VPN can secure connections between traveling officials and presidential servers, it shouldn’t be the sole guarantee. The Presidency could adopt a Zero Trust architecture, operating on the principle that no user, device or network should be trusted by default. Each access request would be verified based on multiple factors:

  • User identity;
  • Device used;
  • Connection location;
  • Document sensitivity level;
  • Assigned permissions;
  • Observed connection behavior.

Accessing presidential files could require simultaneously an institutional computer, digital certificate, encrypted connection, physical security key and local biometric verification on the device.

Exclusively institutional phones and computers

Presidential files shouldn’t be accessed from staff members’ personal phones. Civil Cabinet members, General Secretariat and service personnel handling these documents should use institution-owned equipment administered by a specialized team. These devices should feature:

  • Full encryption;
  • Regular updates;
  • Limited authorized applications;
  • Separation from personal use;
  • Remote wipe capability in case of loss;
  • Automatic lock after inactivity;
  • Prohibition of unsecured public Wi-Fi connections.

A centralized device management solution would allow the administration to install updates, block dangerous applications, revoke devices and remotely delete data in case of theft or compromise.

Anti-phishing authentication

A password, even complex, should never suffice for accessing Presidency files. Authentication should combine several elements:

  • Recognized institutional device;
  • Personal code;
  • Physical security key;
  • Optional local biometric verification.

SMS codes can enhance security but remain vulnerable to certain attacks. For highly sensitive accounts, physical keys and digital certificates offer better phishing resistance. Staff should also receive regular training to recognize fake messages, fraudulent urgent requests, malicious links and attempts to impersonate superiors.

WhatsApp: useful for alerts but not file transmission

WhatsApp is widely used in Cameroon, including in government circles. Its end-to-end encryption protects message and call content during transmission, but this doesn’t make it an official platform for presidential document management. A file shared via WhatsApp remains exposed through:

  • Lost or compromised phones;
  • Screenshot captures;
  • Unauthorized forwarding;
  • Associated devices;
  • Inadequately protected backups;
  • Personal phones of former staff members.

WhatsApp alone doesn’t provide the mechanisms needed for file classification, permission management, version control, validation recording or administrative archiving. The app could be used to announce file availability, confirm meetings, signal emergencies or coordinate travel, but the actual document should never be attached to conversations. The rule could be summarized as: “WhatsApp for alerts and coordination; secure presidential platform for transmission, review, decision-making, signing and archiving.”

Secure government videoconferencing solutions

Remote exchanges between the president and collaborators could use dedicated secure government videoconferencing platforms offering:

  • Encrypted communications;
  • Participant identification;
  • Strict invitation control;
  • Prohibition of unauthorized recordings;
  • Connection log retention;
  • Exclusive use of institutional devices;
  • Data hosting control.

Public links, free accounts and unvalidated applications shouldn’t be used for defense, diplomacy, appointments or government arbitrations.

Document classification by sensitivity level

Not all Presidency documents carry the same risk level. A classification policy could distinguish four categories:

  • Public: Documents intended for dissemination;
  • Internal: Working documents reserved for state services;
  • Confidential: Documents whose disclosure could harm public action;
  • Highly sensitive: Documents related to defense, intelligence, diplomacy, strategic appointments or major arbitrations.

Each level would determine authorized transmission channels, permitted personnel, usable devices, printing capabilities, retention periods and archiving procedures. A public document could be sent via professional email, while a highly sensitive file should only be accessible through a strongly compartmentalized platform.

Complete record retention for every decision

Every consultation, modification, validation or transmission should be automatically logged. Security journals should specify:

  • Who accessed the document;
  • When it was accessed;
  • From which device;
  • What modifications were made;
  • Who validated the final version;
  • When the document was recorded and published, and by whom.

A security supervision center could detect unusual connections, massive document downloads, access attempts from unrecognized equipment or abnormal modifications to official acts. This traceability would also help reconstruct events in case of leaks, intrusions or disputes regarding decision authenticity.

Distinguishing official decisions from social media posts

Presidency Facebook pages and X accounts enable rapid public information dissemination but shouldn’t be confused with systems used to prepare and validate decisions. Before a decree is shared on social media, it must follow a process ensuring:

  • The document was transmitted through authorized channels;
  • The competent authority was authenticated;
  • The final version wasn’t altered;
  • The validation was timestamped;
  • The original is preserved in official archives.

A visible signature on an online image doesn’t constitute complete digital proof by itself. Security relies on the entire preceding process.

Ten priority measures for the Presidency

The Republic’s Presidency could implement ten priority actions:

  1. Mandate professional email under the @prc.cm domain;
  2. Ban personal Gmail, Yahoo and similar accounts for state affairs;
  3. Deploy a presidential electronic document management platform;
  4. Introduce secure institutional electronic signatures;
  5. Provide exclusively professional phones and computers;
  6. Enforce multi-factor authentication resistant to phishing;
  7. Reserve WhatsApp for alerts and coordination;
  8. Classify documents by sensitivity level;
  9. Centralize access logs in a security supervision center;
  10. Train staff regularly on espionage, phishing and information leak risks.

The public record doesn’t confirm whether the Cameroonian Presidency currently uses all these systems. However, they represent minimum security standards every institution handling remote state affairs—finances, diplomacy, security and continuity—should strive to implement.