Insider threats arise from the interplay of technical, organizational , and individual conditions, yet most analytical frameworks address these dimensions separately. This paper presents an exploratory, data-driven approach that combines structured document analysis with a locally deployed large language model in order to identify explicit and implicit technical, organizational, and individual (TOI) factors in tex-tual descriptions of insider-related events. The TOI coding structure is derived from the systematic review by Nassir et al. A hybrid reference corpus of sourced and synthetic indicators is generated under a controlled prompting protocol and verified by hand before being used to calibrate a separate detection model, so that generation and detection remain methodologically independent. Recurring configurations of factors are then compared with the insider profiles defined by MITRE (malicious, negligent, mistaken, and outsmarted) to examine whether specific factor combinations align with distinct insider types. The study is in progress; this paper reports the analytical framework and the corpus construction procedure.