I'd use a flash drive or external hard drive rather than CDs or DVDs, but the manual process I described is what you'll have to do.
I understand bureaucracy very well, and if you've been told you can't connect to the Internet, you can't do it. However wherever you get the updates from IS going to have to be connected to the Internet, and by putting updates on from whatever computer you download onto is no less likely to introduce malware than having the computer connected in the first place.
What I'd do in your case would be to just get another computer at the same maintenance level as the isolated ones and download the updates to that, carefully recording the KBxxxxxx IDs of each one, then manually download them from the MS web site, copy them onto some media, then install them where needed. Of course if they really need to be that isolated, maybe they don't need the updates at all?
Oh well, you probably have no say in the matter, and whoever you're working for doesn't want to hear anything about it anyway. :-) If you've never read the short story "Pigs is Pigs" by Ellis Parker Butler, you ought to download it and read it. You'll get a big chuckle out of it.
Good luck.