Vulnerability and risk analysis are considered in relation to critical infrastructures protection. The complexity of critical infrastructures is presented as a challenging characteristic, which calls for new approaches of analysis and the integration of different modeling perspectives. The concepts of vulnerability, risk and resilience are discussed in details and analyzed with respect to their characterization in critical infrastructures (CIs) and the challenges therein. Recent new perspectives on these concepts and their interpretations are also discussed in relation to their applicability for analyzing CI vulnerability and risk, in view of decision making for protection. Throughout the paper, reference is made to systems like the (smart) electric power grid and the Internet, to further exemplify the concepts and issues discussed