Aside from browsing history, privacy implications, some ISPs insert adverts, into the HTML - possibly opening up the user, to drive by browser exploits…
The reality is, it’s not complicated to add HTTPS, as a feature, so there’s no good reason as to why it’s not implemented - aside from incompetence, or trying to save money, on staff?!