Earlier quoted context omitted.
Keeping things up to date and holding critical infrastructure to higher standards than consumer tech is not a bad idea. Taking things offline and properly airgapped can also work, but wouldn't the cost of that exceed making specialized things and maintaining them? We got into this situation due to cost, not ignorance. Both choices are higher cost than putting ancient devices on the internet.
You can't have both secure infrastructure and Internet exposed infrastructure. I don't know if I'd frame it as incompetence, but it does seem firmly outside the capabilities of current engineering practice. If you need a computer system to be actually secure, rule #0 is absolutely ensure it cannot receive unauthorized inputs of any kind (airgapped, big Faraday cage, JB Weld all the ports, big scary guys with guns, re…
While that works for Chernobyl, if you have a real world systems you might want somewhat more practical access.
Of course exposing industrial hardware directly on the internet is the other extreme, and you get what you're asking for.
Do something in between, if you even just apply normal network security you'll be ahead of the pack.
Problem is, a lot of these systems are not built by IT people. While they have a lot of quite admirable skills, it's just not their primary job, and thus they tend to lack the necessary paranoia at times.