Sep 23, 2025 • Wiz Security Research
Wiz + HCP Terraform: Close the IaC-to-Cloud Infrastructure Security Gap
This article announces the general availability of the Wiz HCP Terraform connector, designed to bridge the security gap between Infrastructure as Code (IaC)...
Executive Summary
This article announces the general availability of the Wiz HCP Terraform connector, designed to bridge the security gap between Infrastructure as Code (IaC) and cloud infrastructure. The integration offers zero-configuration code-to-cloud mapping, enabling security teams to trace cloud risks directly back to their source code. While no specific threat actors or malware families are identified in this announcement, the tool addresses risks associated with cloud misconfigurations and infrastructure vulnerabilities. By enhancing visibility into IaC pipelines, organizations can mitigate potential security gaps before deployment. This solution supports proactive defense strategies rather than reactive incident response. Security teams should leverage such integrations to maintain robust cloud hygiene. No active campaigns or malicious entities are reported herein. The focus remains on improving security posture through automated mapping and risk tracing capabilities within the Terraform ecosystem.
Summary
Announcing the GA of our HCP Terraform connector, featuring new zero-configuration code-to-cloud mapping that traces any cloud risk back to its source.
Published Analysis
This article announces the general availability of the Wiz HCP Terraform connector, designed to bridge the security gap between Infrastructure as Code (IaC) and cloud infrastructure. The integration offers zero-configuration code-to-cloud mapping, enabling security teams to trace cloud risks directly back to their source code. While no specific threat actors or malware families are identified in this announcement, the tool addresses risks associated with cloud misconfigurations and infrastructure vulnerabilities. By enhancing visibility into IaC pipelines, organizations can mitigate potential security gaps before deployment. This solution supports proactive defense strategies rather than reactive incident response. Security teams should leverage such integrations to maintain robust cloud hygiene. No active campaigns or malicious entities are reported herein. The focus remains on improving security posture through automated mapping and risk tracing capabilities within the Terraform ecosystem. Announcing the GA of our HCP Terraform connector, featuring new zero-configuration code-to-cloud mapping that traces any cloud risk back to its source. Announcing the GA of our HCP Terraform connector, featuring new zero-configuration code-to-cloud mapping that traces any cloud risk back to its source.