The email arrives at 7.43 in the morning. It looks like a delivery notification — a parcel held at a depot, a link to rearrange. Morgan sees it on the way to a client call and clicks. Nothing seems to happen, so Morgan carries on.
Forty miles away, the same email lands in Sam’s inbox at the same moment. Sam works for a financial services company with six hundred employees, a security operations team, and a contract with a threat intelligence provider. The email is quarantined before Sam ever sees it. A flag is raised. An automated report is filed, and the morning continues.
Two people. One threat. Two different outcomes. The difference had nothing to do with vigilance, and nothing to do with the quality of the device in their hands. It had everything to do with who they worked for.
Morgan is a freelance designer — three years in business, a small client base, a laptop and a broadband connection. The click does what clicks do when a link is malicious. By lunchtime, Morgan is locked out of a client’s shared folder. By the following morning, invoices are going out in Morgan’s name, redirecting payment to an account nobody at that end has heard of.
The next seventy-two hours involve a bank, a report to the City of London Police’s Report Fraud service, a client who is understanding but worried, and a second client who is not. Morgan finds the National Cyber Security Centre’s free guide for small businesses. Then its Cyber Action Plan, and then Check Your Cyber Security — all free, all built for exactly this situation, all written by people who know what they are talking about.
None of them is a system. They tell Morgan what to check and what to change. They do not sit in front of the inbox at 7.43 and stop the email arriving. That is the distinction the conversation keeps missing: advice is available to everyone, and infrastructure is not.
The phishing email was not sophisticated. Across the same city that morning, the same email was intercepted and neutralised at organisations with security operations teams, by automated systems most of their employees had never thought about. Morgan did not have access to those systems. Morgan had access to the same email.
There is a word for what happened here, and it is not misfortune. It is structural.
Cybersecurity protection in the UK is distributed by employer, not by need. The protections that stopped Sam from ever seeing that email exist because Sam’s organisation can afford to buy them, maintain them and staff them. They are not public infrastructure. They are private expenditure, scaled to the size of the organisation that funds them.
The scale of that gap is measurable. The government’s Cyber security breaches survey, published on 30 April 2026, found that 76 per cent of large businesses have a formal incident response plan. Among micro businesses the figure is 21 per cent. Across all UK businesses, only 11 per cent use or invest in threat intelligence at all — which means the arrangement Sam’s employer has is not standard practice. It is a purchase, and most organisations cannot make it.
The sole trader, the freelancer and the small charity face the same threats as the organisations with the security operations centres, and they face them on their own account. The conversation about what individuals should do — stronger passwords, updates, wariness about links — is not wrong. It is aimed at the wrong layer. Sam was not protected by being careful. Sam was protected by a payroll.
For Morgan, the consequences are immediate: three days of lost work, and two client relationships that will take longer than three days to repair.
The phishing email does not check who you work for before it decides to arrive.
There is a second consequence that takes longer to see. Small businesses are not peripheral to the UK economy. Businesses with fewer than fifty employees account for 13.1 million jobs — 47 per cent of private-sector employment, on the Department for Business and Trade’s 2025 figures. When that part of the workforce is disproportionately exposed to cybercrime and disproportionately unprotected against it, the cumulative cost is not a collection of individual misfortunes. It is a structural tax on the least resourced part of the economy, levied by criminals who understand the asymmetry better than the policy conversation does.
None of this is about the technology failing. Sam’s system did exactly what it was built to do: the email was quarantined, the morning continued, the harm never arrived.
Enterprise security works partly because it learns the organisation it sits inside. It knows which invoices are normal, because it has watched a year of them. A freelance designer with the same shared folders and the same monthly invoice cycle is exactly that kind of predictable context. Nobody built it for Morgan. The problem was never that a single inbox is too complicated to protect — it is that a single inbox was never going to pay for it.
My Opinion
I don’t think this is really about awareness, though the conversation usually pretends it is. Morgan didn’t fail to ask the right question — Morgan didn’t know there was a question to ask, and neither do most sole traders and freelancers I’ve worked alongside. The tools that would have stopped that email exist and work. What’s missing is the money, and the confidence to spend it on something that feels invisible until the day it isn’t. I think government should treat this the way it treats other public safety problems it doesn’t leave to the market alone — by funding working protection for the self-employed and the smallest businesses, not another campaign telling them to be more careful.
If you’ve been on the wrong side of it
Does the protection you work behind reflect what you actually need, or what your employer happened to buy?
If you have been through something like this, or watched someone close to you go through it, what did the gap between the threat and the available help look like from the inside?
For anyone who has bought security for a small organisation: what did you get for the money, and what did you find you still could not buy at that size?
And if you have moved between employment and working for yourself, what changed about your exposure that nobody warned you about?
The argument behind this article is developed in my book The Shadow System, specifically the chapters on The Corporate Digital Divide and The Unbearable Asymmetry in Part III, which examine how the gap between governed and ungoverned security has become one of the defining structural problems of the digital economy.
Authors Note
These are fictional characters. Their story is drawn from a combination of professional observation and personal proximity to real events. The experiences described are real. The person is not.
You’re reading The Next Evolution by Neil Catton, articles that explore the human world and the intersection of technology, they try and ask difficult questions - not to scare - but to inform. If someone forwarded this to you, you can subscribe free at neilcatton.substack.com.
Neil Catton is the author of The Next Evolution, The Cognitive Crucible, The Shadow System and Working as Designed available on Amazon, and writes at the intersection of technology, ethics, and human purpose.


