Earlier quoted context omitted.
Ideally those incentives would be combined with disincentives for those organizations to continue breaking the web. A combination of the two seems more likely to be successful than either alone.
tcp != the web. Also, most firewall don't break TCP, they break HTTP(S) because they want levels of control.
And it's because they want levels of control on the least affordable place. They wouldn't need to break anything if they added the supervising software to the endpoints.