First, it's the neighborly thing to do. Blocking infected systems reduces the spread of malicious software on the Internet. Second, with fewer machines flooding the network with their wares, it conserves bandwidth, reducing costs for the ISP.
So why don't many ISPs do this? Quite simply, it can make customers angry. Many ISP customers expect unfettered access to the Internet, and they are not willing to tolerate "false positive" alerts that cause the temporary blocking of their systems while the matter is resolved.
There is a decent compromise that many ISPs adopt: notifying the owners of infected systems that they have security issue(s) on their network that require remediation. I would recommend this approach because it constitutes due diligence on the part of the ISP by informing the customer of the discovery without risking the client relationship due to an accidental disconnect.
This was first published in March 2008