That should work if all VO users are members of the View ONLY group, and if you do the same for all other lifecycle states besides "Released" (although I am not sure which one you have there would be the Released state you mentioned before).
In Vault, setting DENY permissions is a bit "harsh" and heavy-handed. Usually, it is best to ALLOW Everyone or the groups you like to access what you need them to access, and implicitly deny access to states and lifecycles (and folders) by not setting users and groups with the Allow permissions where that matters. But that can be a tad complicated too, although more elegant.
By the way, you can always check if this works by right-clicking a file in question in WIP state, then go to Details > Effective Permissions, and add the View ONLY group to see what their access would look like.