For anyone interested, moving my WAN connection to the ONT from the built-in 2.5G copper WAN interface on the UDM-Pro SE to a UF-RJ45-1G SFP 1G SFP module in the 10G SFP+ slot took the performance with medium IDS/IPS settings from 750-800Mbps back up to full line rate - now hitting 918/110 even with high IPS/IDS settings. There is a very clear difference in the performance from the switch to the SFP module, so it is well worth the £25 or so on a £600 device. I could have done it cheaper with an off-brand SFP, but I fancied the easier route and so decided to get the Ubiquiti one.
It's a shame the UDM-Pro SE 2.5G WAN performance seems to let the side down a bit once you add PPPoE, IDS/IPS, and a fast connection, but anyway now I'm fully up to speed with a non-GEA connection that isn't adding a network constraint, and all the router features I wanted enabled.
The only slight outstanding annoyance is that with all these things improved you are still left on Zen with the gateway lottery. I've seen quite a few connections to the Manchester gateways in recent days, which I do quickly drop if I notice, but slightly more sinister is the difference in single threaded throughputs on the various London gateways. Anyway, it will do for now, but I think I'm going to be shopping for a new provider in May.