Imagine a customer finds your business, clicks through to your website, and the first thing their browser tells them — in plain language, right next to your name — is 'Not Secure'. Whatever you were about to say about quality and trust, that warning just undermined it. Many visitors won't read past it.
The frustrating part is how easily it's fixed, and how many UK businesses still trip over it. Understanding HTTPS and SSL takes about five minutes and removes one of the most needless ways to lose a customer's confidence.
What the padlock is really telling you
When you visit a website, look at the address bar. A site beginning with https:// (often shown with a padlock) has a secure, encrypted connection. A site on plain http:// gets the 'Not Secure' label.
The 's' stands for secure. It means the data travelling between your visitor's browser and your website is encrypted — scrambled so that even if someone intercepts it on the way, they can't read it. Without it, information like form entries and passwords travels in plain text that a determined eavesdropper on the same network could read.
SSL vs HTTPS vs TLS — untangled
The terminology trips people up, so here it is plainly:
- SSL certificate — a small digital file installed on your server that proves your site's identity and enables encryption. (Technically the modern version is called TLS, but everyone still says 'SSL'.)
- HTTPS — the secure version of your web address that you get once the certificate is installed and working.
In short: install an SSL certificate, and your site runs on HTTPS. They're two sides of the same coin.
Why it matters for your business
Customer trust
The 'Not Secure' warning is visible, alarming and right where people decide whether to trust you. On any page with a form — contact, enquiry, checkout — it directly suppresses the action you want visitors to take.
Search rankings
Google has confirmed HTTPS as a ranking signal. It won't catapult you up the results, but combined with the trust effect it's worth having for your search visibility.
Legal and data duties
If you collect any personal data, encrypting it in transit is part of handling it responsibly under UK GDPR. It's one of the basic security measures regulators expect.
Functionality
Some modern browser features and payment integrations simply won't work over plain HTTP. HTTPS is increasingly a technical prerequisite, not just a nicety.
How to fix a 'Not Secure' site
| Step | What happens |
|---|---|
| 1. Get a certificate | Often free via Let's Encrypt; many hosts include it |
| 2. Install it | Your host or developer activates it on the server |
| 3. Redirect HTTP to HTTPS | All traffic is forced to the secure version |
| 4. Fix mixed content | Update any images or scripts still loading over HTTP |
| 5. Update references | Tell Google and update internal links/sitemaps |
Most reputable UK hosts now offer free SSL with one-click activation. The step people miss is mixed content: if your secure page still loads an image or script over insecure HTTP, browsers may keep showing a warning. Fixing those references completes the job.
Do you need to pay for an SSL certificate? For the vast majority of businesses, no. Free certificates from Let's Encrypt are trusted by every major browser and renew automatically. Paid ones add extra validation that mostly matters to banks and large enterprises.
Common pitfalls
- Expired certificates. Certificates renew periodically; if auto-renewal fails, your site can suddenly show a scary error. Monitoring catches this.
- Forgotten redirects. Without forcing HTTPS, visitors can still land on the insecure version.
- Lingering mixed content. One old hard-coded HTTP image can break the padlock on an otherwise secure page.
Getting it sorted
If your site currently shows 'Not Secure', it's almost always a quick, inexpensive fix — frequently free if your host supports it. If you're not comfortable touching server settings, a developer can sort it, including redirects and mixed content, in well under an hour.
Browse experienced web development specialists in our directory if you'd like it handled properly, or ask your current host whether free SSL is already available on your plan — it often is.