Employees play a pivotal role within an organization in protecting its assets and sensitive information. However, employees are the most vulnerable entity and the weakest link in cybersecurity. The study presents a Systematic Literature Review (SLR) and identifies different factors influencing an employee’s information security awareness and their behavior, by specifically focusing on variables beyond effective training and education programs. The study resulted in 35 eligible publications across selected databases and digital libraries from 2020 to 7 April 2025, where all 35 publications were analyzed through thematic analysis. The publications were mapped to different themes, resulting in 6 themes and 18 subthemes representing different factors of promoting an employee’s information security awareness and their behavior, and factors leading to employees being non-compliant in their security behavior. The factors promoting an employee’s information security awareness and their behavior were organizational support, psychological factors, and organizational culture. In contrast, non-compliant factors were psychological factors, attitude and beliefs, and time. The findings advocate for the consideration of creating a security culture within an organization with the management supporting the employees, which could enhance an employee’s ability in adopting a security behavior.