You are correct. ICO has a high risk to investor but there are some certain rules that i follow when choosing an ICO I Hope this will help
1. "Timing" does the current market need this project ?
2. "Project" what problem do they solve ? Does the people need this project ?
3. "Team" can it be executed by the team ? are they composed of a team who can build the project they have proposed
4. "Token Metrics" Are they to Greedy ? or those the token metrics respects the community or just the investors within ?
5. "Instincts and Experience" you may encounter many ICO projects ICO are simply like choosing a friend if you have a bad feeling about the ICO you better stay out
I Hope This Helps a lot