Randy Trzeciak is a researcher at Carnegie Mellon’s CERT Insider Threat Center. He says organizations can mitigate the risks posed by unintentional insiders who, by mistake or through social engineering, compromise sensitive information. Organizations can introduce technical controls that could help minimize the impact of, for example, an employee clicking on a phishing e-mail and allowing malware onto the network, he says. The unintentional insider threat is defined as: “A current or former employee, contractor, or business partner who has or had authorized access to an organization’s network, system, or data””]
Source: https://www.govinfosecurity.com/managing-unintentional-insider-threats-a-6274