Dabish Digital
Security

A practical checklist for HTTPS and SSL

There is no clever trick in this one, just a handful of decisions worth making deliberately. Run through this the next time HTTPS and SSL comes up.

Security is a maintenance habit rather than a purchase, which is why it drifts. If it only works because one person remembers to do something, it does not work yet.

The checklist

  • Browsers now actively warn on unencrypted pages
  • Certificates can and should renew automatically
  • Mixed content quietly breaks the padlock
  • Someone is named as the owner
  • There is a date to review it again

Why this earns attention

Browsers now actively warn on unencrypted pages. None of that requires a large budget, only a decision and someone to own it. If two people in the business would answer this differently, that gap is the actual problem.

In practice

The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about HTTPS and SSL before you move on:

  • Someone can say what the current setup is without going to look
  • Certificates can and should renew automatically — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If any of that sounds like a description of your current setup, it is fixable.