I can't help but think that it would make sense for Mr. Yau to either (a) Change the server setting to emit the X-Frame-Options: DENY header or (b) monetize views on his graphic. In general, you can't assume people won't deep-link your content, and that includes embedding. Taking steps to protect against or take advantage of traffic spikes is the responsibility of a content provider. This, of course, wouldn't protect…
The article states that the Daily Mail scraped the files and uploaded them separately, to avoid his iframe detecting JS.
And "just monetize it" feels like a... simplistic approach. Even if the Daily Mail did a normal iframe embed, how would the author monetize, exactly?