As a side note, several years ago, I had a friend who worked for a small research company that had a ban on encryption software. Installing or using PGP on a company computer would be cause for termination.
I expect to see these ideas become more mainstream. In future, companies may only allow certain encryption technologies on their networks/nodes (ones which they hold keys for).
Where I worked moving encrypted files over plain FTP was preferred by the business clients because they controlled the encryption passphrases, whereas using SFTP would require operations support, as ops own certificates and encrypted service endpoints.
Much easier for a business user to encrypt a file on their computer using PGP and FTP it to the recipient, passing the passphrase out of band, than raise a service request to pick-up and transmit a file dropped onto a specific egress zone.
(S)FTP support has been baked into huge ERP systems like Oracle and SAP for years (I would be very surprised if BitTorrent was even on a list of development features), and when you're working with a company who has a $100mm SAP installation, you transfer files using (S)FTP.
I just finished a large integration with SAP where all of the data was transferred using files over SFTP. We have a modern REST API they could use as well, but that would've added a lot longer time to the integration as it wasn't already baked into SAP (plus, moving large files over HTTP is not ideal).