Dabish Digital
Security

A short guide to HTTPS and SSL

It is rarely the thing that gets a project approved, and often the thing that decides how it goes. Everything we would tell a client about HTTPS and SSL in the time it takes to drink a coffee.

The realistic threat for most small businesses is automated and opportunistic, not targeted. The version that survives contact with a real deadline is the simple one.

What it costs to ignore

Browsers now actively warn on unencrypted pages. Small and consistent beats large and occasional here. If two people in the business would answer this differently, that gap is the actual problem.

What good looks like

Certificates can and should renew automatically. Getting it slightly wrong is survivable. Ignoring it entirely is not. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.

The mistakes we see most

Mixed content quietly breaks the padlock. There is a version of this that is over-engineered, and it is worth avoiding. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.

The short version

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about HTTPS and SSL before you move on:

  • Someone can say what the current setup is without going to look
  • Mixed content quietly breaks the padlock — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If any of that sounds like a description of your current setup, it is fixable.