We need regulation requiring ISPs to care. In the US they will severely reduce your speeds (if not outright cancel your account) over repeated DMCA complaints so why can't they do the same for reported botnet activity?
I guess logistically they'd need a way to assess if the problem had been resolved though. It would be pretty challenging to validate reports and then follow up on them in an automated manner. There's not going to be much budget for this after all. Still you'd think it could be done for the largest (and thus well understood) botnets.