If you use Apache, set a rewrite rule for files to be refused to be downloaded. Check Apache.org for the appropriate syntax
i.e.
RewriteRule /path/to/dir/secret.dat$ http://www.yahoo.com
any time anybody tries to access that through a web-server then they'll get redirected to yahoo.com
For FTP access it might be a little different though, now that I think about it, how about putting the files in another folder a separate from the ftp root? so that they can't download it. or in UNIX change access permissions so that user and group and download it while the "nobody/everybody" group has no access.