I hear where your coming from with this but as HPKP & HSTS becomes more prevalent MITM decrypt will be impossible.
What are web security vendors doing to enable the industry and the like the ability to intelligently safeguard those who we are responsible for ?
Personally I can't see how, without being hooked into GCHQ/NSA etc will we ever be truly able to inspect web traffic for any meaningful monitoring / reporting. Assuming that HPKP/HSTS in the not too distant future maybe we are destined to a hiding. This is making the move away from our current vendor ( not through choice ) extremely diffiucult as no one appears to actually fully able to converse what we are obliged to do. Ofsted themselves appear clueless, as long as you can prove that users are unable to get to obvious type web sites and you can report seems to suffice, but we know that isn't really the case these days.
Be interested in others viewpoint.