Yep. WSUS Offline for the windows boxes (although most of my offline windows installations are XP VMs so they are already as fully patched as they are ever going to be). Then we have an Umbongo server that serves all the Umbongo patches to the various offline workstations that host the VMs. A download script and a bit of rsyncing and the update server stays fresh.
The only issues are the rare times someone needs a MS patch that isn't covered by WSUS Offline, in which case they deal with it manually using MBSA.
Actually the hardest bit is getting the old-as-hills patches for various tools that we need to run. But running them offline doesn't make getting them in the first place any worse.