Insider threats, originating from current or former employees, contractors and trusted business partners who are with authorised access to organisational resources continue to pose a critical security challenge across multiple sectors. These threats may be intentional (malicious) or unintentional (accidental) and are shaped by the interaction between technical and human factors. This systematic literature review analyses 121 studies published between 2014 and October 2025 to address two key research questions: (1) which human factors contribute to insider threats, and (2) whether existing technical methods, particularly machine learning approaches, have been applied to predict or detect insider threats on the basis of human factors. The review introduces a taxonomy of human factors influencing insider behaviour and provides an examination of technical approaches, including detection methods. The findings highlight a substantial gap in machine learning research directly linking human factors to insider threat detection, largely due to the absence of datasets that integrate behavioural and contextual human attributes. By synthesising current knowledge and identifying these limitations, this study outlines key challenges and research opportunities, underscoring the need for predictive models that capture the complex role of human factors in insider threats especially in unintentional insider threats.
Pathirana et al. (2026) studied this question.