I downloaded the XP patch on the new PC. I'm not even sure I have SP3 on the old box. It may still be on SP2, so I don't know if it'll work. I'll disconnect the ethernet before I even power it on. If I can't patch it, I guess it stays offline until I find an alternate solution. (I think some port blocks might do. Kerio Personal Firewall 2.x blocks everything by default anyway; just have to make sure no rules allow the involved ports.)
Que, what I do after I'm happy with the state of my updates is disable the Windows Update service and the Windows Modules Installer service (in services.msc). That kills Update and all hogging of the CPU. It also kills the Windows Store (which I never use). Apps I have continue to work, but won't update, and I can't get new ones. (So this won't work well for anyone invested into Microsoft's walled garden.) When I choose to update again, I find the cumulative standalone msu file in that catalog site I linked above and download it. Then I disconnect from the internet, reenable the 2 services (manual and automatic, respectively, were the initial settings for me), launch the msu, and let it do its thing. After the reboot and completion of updating, I disable the 2 services again, and finally reconnect to the internet. It's a chore, but it gives me exactly what I want, which is full control over updates, and a nag-free environment.