You can use something called a data diode. These are used in high security networks to provide secure one way communication (insecure->secure). The idea is that if there _is_ communication it's not possible to exclude compromise completely. However if you do get compromised no information can escape a network with one way traffic, so an attacker might only destroy your information.
Funnily enough, someone else thought to use a raspberry pi for this purpose too: https://www.raspberrypi.org/forums/viewtopic.php?t=58957&p=5...