New threat intelligence primarily impacts the frequency component of risk calculations. CRISC states: "When new information about threats is available, it must be incorporated into risk assessment by adjusting threat event frequencies in related scenarios." * A and D are statistical manipulations, not practical first steps. * C addresses impact, not likelihood. Hence, B. Revise the threat frequency is correct. CRISC Reference: Domain 2 - IT Risk Assessment, Topic: Incorporating Threat Intelligence.