Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
Put pressure on ISPs to make them take responsibility for traffic originating from their networks. They have the the tools to notify customers if customer is sending suspicious traffic (and if necessary, they can temporarily shutdown the connection).