In it's native form S1 interface is not so secured except that in most of the cases operator uses private network to backhaul the S1 interface, which may be considered as secured.
IPSec is the 3GPP standardized solution for S1 interface security. Use of IPsec ensures integrity and confidentiality of the traffic between the eNBs and the core network.
However IPsec adds additional transport overhead (increases from 15% to approximately 25%) and also typically requires IPSec gateway at core network side.
In practice operators may implement IPsec only in specific scenarios where eNBs uses public (untrusted) backhaul to connect to core network, e.g. HeNB etc.
By the way, for IP offload, LIPA or SIPTO are expected to be employed. LIPA is used to offload the IP traffic within the enterprise avoiding the mobile core network, whereas SIPTO is used to selectively offload the IP Traffic over internet by avoiding the mobile core network for the Data traffic.