Dabish Digital
Security

When HTTPS and SSL is worth the effort

It is rarely the thing that gets a project approved, and often the thing that decides how it goes. HTTPS and SSL is not free, and pretending otherwise leads to bad decisions.

Security is a maintenance habit rather than a purchase, which is why it drifts. It is worth deciding this deliberately rather than inheriting whatever the last person set up.

When it is worth it

Browsers now actively warn on unencrypted pages. It is worth being explicit about, because assumptions differ quietly. Budget a little time for it every quarter and it never becomes a project of its own.

When it is not

If nothing downstream depends on it and nobody is complaining, it can wait. None of that requires a large budget, only a decision and someone to own it.

How to decide

Mixed content quietly breaks the padlock. The teams that handle this well are rarely the ones with the biggest budgets. Assume whoever inherits this will have half your context and none of your patience.

In practice

The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about HTTPS and SSL before you move on:

  • Someone can say what the current setup is without going to look
  • Certificates can and should renew automatically — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If you are not sure where your systems currently stand on this, it takes us about an hour to find out.