Besides, he didn't suggest they bootstrap their own CDN. It could be as simple as creating a Cloudflare account.
Any further guesses as to how "important" the organisation is is pointless in the absence of understanding the actual use case.
It's more the equivalent of putting it in an envelope marked Private and Confidential than locking it in a box.
In many of these cases the password is in the email the file is sent with.
IMO, the primary benefit of encrypting pdf in email is stopping the email service provider from scrapping the pdf.
Except with digital watermarks. Photocopiers generally recognize things like currency and refuse to copy at high fidelity. The PS3 I believe would refuse to play ripped cinema soundtracks all the way through, using audio watermarking. It's conceivable that cameras could be required to do the same thing for digital restriction watermarks.
I guess they could try to do a denial of service attack on the typist by deliberately overusing letters from the same vertical keyboard row to wear out the finger.
In that case a third party is the answer and has been the answer forever - if only the bank has a paper record of your mortgage then you have no guarantees they won't alter that contract on the sly - if it's lodged with a mutually trusted third party that doesn't have a vested interest with either participant then you're safe. The best I've ever seen with physical documents is a guarantee that the document hasn't been tampered with, but there isn't really a way to prove which document is the real document.