Controls & technical basics
An agreed, simulated attack in which skilled testers try to break in, to show how well systems really hold up.
Formal
An authorised test, limited in scope and time, in which people use the same methods as real attackers to find and actually use weaknesses, chaining them together to show what an attacker could reach.
In plain English
Like hiring a professional burglar to try to break into your shop, with your permission, and then write down exactly how they got in.
In practice
Testers hired by a Danish region find a forgotten test website, use a weak password there to get onto the network, and within two days show the IT security manager they can read the finance folder.
Why it matters
Lists of weaknesses do not show how they combine; seeing a real path from outside to valuable data convinces management and shows what to fix first.