I used to think that at first. BUT...I don't want to support "all the other stuff at a home, which will have issues with a UTM at the edge". IoT stuff, oh..the kids games. Streaming TV issues. More of the kids games. Double NAT issues because reconfiguring the ISP supplied gateway didn't happen. More kids games stuff. XBox, Playstation. Endless new IoT stuff. Yeah the list goes on and on and keeps repeating.
What we do is...use secure methods to connect remote workers.
Many use personal devices to connect. Can have Splashtop Business client on their home rig, they remote into their office computer. I don't care how badly infected their home rig is, it will not transfer through a remote desktop connection/splashtop client to host connection. RDP to terminal server/TSGateway....also safe/immune from transferring bugs.
Many of our clients setup on 365 now....Teams/Sharepoint for files, etc. Advanced threat protection scanning the files, and from personal computers...just done through a browser. Really little chance of infection there.
VPNs...well..VPN into HQ...actually CAN BE a point of infection, as with many VPN setups...a client connection brings that computer onto the central network. Some VPNs do that more securely than others..but....