You mention crappy security practices from the ISP but then mention the user's action (installing "free" VPNs). Why is the ISP on the hook for the user making terrible decisions?
What is the correct security practice in that instance? Fire the customer for being an idiot? Maybe just DENY IP ANY ANY on outbound traffic?
How do you protect somebody who is intent on running themselves off a cliff?