The point I am trying to make here is that ISPs should much more engaged in this entire process.
most of the larger isps have reasonable security teams with some good folk. but you need to be much more specific about what you want from medium and smaller isps, and what the immediate payoffs (cf. the financial secions of the newpaper) will be to them to justify the costs.
just whining that no one will come out to play is not a success strategy, as you say you have well demonstrated.
be specific, like "if you run X tools the payoff will be Y." randy