You have to install company root certificates on clients, perhaps even merely self-signed ones if they've been particularly cheap and lazy. Then traffic needs to be routed through a firewall / proxy as well.
This in turn can lead to issues with tools such as Maven or NPM. These issues can be hard to debug.
Besides, if you don't know what you're doing - and most companies don't specialise in network security - it's easy to get the setup wrong and create major security problems.
Sometimes the motivation isn't so much protection against malware but rather a petty desire to know what employees are doing.
For these reasons I'd strongly advise against this practice.
As for alternatives:
Follow and encourage the use of accepted best practices.
Educate and trust your employees about security.
There are a number of whitelisted URLs (banks, and services that refuse to work with a MITM'ed cert) but other than the initial headache during implementation, it is pretty seamless now.
It's usually done as part of a firewall that will MITM traffic on the network.
And easily defeated by certificate pinning.