Note: this only describes cases I'm familiar with, in the US. I bet that some countries with more experience on the receiving end of cyber-warfare (e.g. Ukraine) are better.
The main line of defense is these days is "layers of an onion" network with (physical) controls such that data easily can get out to a higher layer but that it is very difficult to get in from a higher layer back down into a deeper layer.
A completely airgapped network is not practical anymore because the alternative is even worse: nobody wants to have dozens or 100ths of operators, maintenance engineers and 3rd party contractors running around the facility with usb sticks because there is no network to move stuff around. If you have a network then you can control where the data comes into your network, who copies the data to where and what data is visible for which user.
Let data flow one way from the secure industrial equipment out to the general use network for monitoring, but you'd still have to go to a machine on the secure side to make any changes.