The COVID-19 pandemic was an example of an adverse event that created temporary operational conditions for critical infrastructure (CI) operators. From remote work patterns to cybersecurity workforce absenteeism, cybersecurity incident management had to consider different risk indicators and adapt technology (e.g., detection of anomaly patterns) or processes (e.g., prioritization or ingestion of external threat intelligence). The use and sharing of cyber threat intelligence (CTI) proved to be valuable to stay up to date, but challenges related to trust and confidence emerged. This paper, included as a chapter within the book Technology-Enabled Resilience: Innovations in Critical Infrastructure Protection, describes the design of a dynamic solution to be used by cybersecurity operators, which was validated in the SUNRISE project pilots with several CI operators.