Why HTTPS and SSL matters more than it looks
We end up explaining this on discovery calls often enough that it deserved writing down. HTTPS and SSL is easy to treat as a detail, and that is exactly why it is worth a few minutes of attention.
Security is a maintenance habit rather than a purchase, which is why it drifts. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
What is actually at stake
Browsers now actively warn on unencrypted pages. This is the sort of thing that compounds, quietly, in both directions. The version that survives contact with a real deadline is the simple one.
Certificates can and should renew automatically. Getting it slightly wrong is survivable. Ignoring it entirely is not. Doing this properly once is usually cheaper than doing it approximately three times.
Common failure modes
Mixed content quietly breaks the padlock. This is the sort of thing that compounds, quietly, in both directions. If two people in the business would answer this differently, that gap is the actual problem.
In practice
The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about HTTPS and SSL before you move on:
- Someone can say what the current setup is without going to look
- Browsers now actively warn on unencrypted pages — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Worth checking on your own setup before it becomes someone else's problem to fix.