I don't really mean to be the annoying one, but not having Internet on the dev machines would be extremely retarded. The solution is to have the network isolated and fed by an extremely secure server, where Internet traffic can't be directly targeted toward the machines--just the server. Then, all the dev machines should run solid firewalls and antivirus programs.
Automatically have all net traffic logged and refuse service permissions under all circumstances. Also, only allow like email/http/ftp access with a "virtual buffer" system in place where all data is pooled instead of being directly sent, where it can be scanned and more particulars of malicious intent filtered.
It could still be compromised, but it would be very remote.