Doesnt matter if the computer is airgapped if the passphrase is weak
If the cold storage is properly set, meaning it will never reach the internet, ever, the passphrase can even be empty!
OP will have watch-only wallet online which will be used to create the transactions and broadcast them and the intermediary step of signing them will be done by transporting the tx file with an USB stick to the offline cold storage.
The only security risk is the USB stick, but it's easy to configure to never actually run anything off it and it's OK.
Edit: I've set recently, for a test, a cold storage on Tails live OS with Electrum and it worked wonderfully.