Web Development

HTTPS, SSL and Why Browsers Flag "Not Secure" Sites

What the padlock, the 'Not Secure' warning and SSL certificates actually mean for your business.

The Editorial Team · 22 May 2026 · 3 min read

Imagine a customer finds your business, clicks through to your website, and the first thing their browser tells them — in plain language, right next to your name — is 'Not Secure'. Whatever you were about to say about quality and trust, that warning just undermined it. Many visitors won't read past it.

The frustrating part is how easily it's fixed, and how many UK businesses still trip over it. Understanding HTTPS and SSL takes about five minutes and removes one of the most needless ways to lose a customer's confidence.

What the padlock is really telling you

When you visit a website, look at the address bar. A site beginning with https:// (often shown with a padlock) has a secure, encrypted connection. A site on plain http:// gets the 'Not Secure' label.

The 's' stands for secure. It means the data travelling between your visitor's browser and your website is encrypted — scrambled so that even if someone intercepts it on the way, they can't read it. Without it, information like form entries and passwords travels in plain text that a determined eavesdropper on the same network could read.

Key takeaway: HTTPS is now the baseline expectation, not a premium feature. An SSL certificate is usually free, takes minutes to set up, removes the trust-destroying 'Not Secure' warning, and gives a small SEO boost. There's no reason to be without it.

SSL vs HTTPS vs TLS — untangled

The terminology trips people up, so here it is plainly:

  • SSL certificate — a small digital file installed on your server that proves your site's identity and enables encryption. (Technically the modern version is called TLS, but everyone still says 'SSL'.)
  • HTTPS — the secure version of your web address that you get once the certificate is installed and working.

In short: install an SSL certificate, and your site runs on HTTPS. They're two sides of the same coin.

Why it matters for your business

Customer trust

The 'Not Secure' warning is visible, alarming and right where people decide whether to trust you. On any page with a form — contact, enquiry, checkout — it directly suppresses the action you want visitors to take.

Search rankings

Google has confirmed HTTPS as a ranking signal. It won't catapult you up the results, but combined with the trust effect it's worth having for your search visibility.

Legal and data duties

If you collect any personal data, encrypting it in transit is part of handling it responsibly under UK GDPR. It's one of the basic security measures regulators expect.

Functionality

Some modern browser features and payment integrations simply won't work over plain HTTP. HTTPS is increasingly a technical prerequisite, not just a nicety.

How to fix a 'Not Secure' site

StepWhat happens
1. Get a certificateOften free via Let's Encrypt; many hosts include it
2. Install itYour host or developer activates it on the server
3. Redirect HTTP to HTTPSAll traffic is forced to the secure version
4. Fix mixed contentUpdate any images or scripts still loading over HTTP
5. Update referencesTell Google and update internal links/sitemaps

Most reputable UK hosts now offer free SSL with one-click activation. The step people miss is mixed content: if your secure page still loads an image or script over insecure HTTP, browsers may keep showing a warning. Fixing those references completes the job.

Do you need to pay for an SSL certificate? For the vast majority of businesses, no. Free certificates from Let's Encrypt are trusted by every major browser and renew automatically. Paid ones add extra validation that mostly matters to banks and large enterprises.

Common pitfalls

  • Expired certificates. Certificates renew periodically; if auto-renewal fails, your site can suddenly show a scary error. Monitoring catches this.
  • Forgotten redirects. Without forcing HTTPS, visitors can still land on the insecure version.
  • Lingering mixed content. One old hard-coded HTTP image can break the padlock on an otherwise secure page.

Getting it sorted

If your site currently shows 'Not Secure', it's almost always a quick, inexpensive fix — frequently free if your host supports it. If you're not comfortable touching server settings, a developer can sort it, including redirects and mixed content, in well under an hour.

Browse experienced web development specialists in our directory if you'd like it handled properly, or ask your current host whether free SSL is already available on your plan — it often is.

Frequently asked questions

What does 'Not Secure' actually mean?
It means the site isn't using HTTPS, so data between the visitor and the site isn't encrypted. Anyone able to intercept the connection could potentially read what's sent, including form entries. Browsers show the warning to alert visitors.
What's the difference between SSL and HTTPS?
SSL (technically now TLS) is the security certificate and encryption technology. HTTPS is the resulting secure version of your website address. Installing an SSL certificate is what lets your site run on HTTPS.
Do SSL certificates cost money?
Often not. Free certificates from Let's Encrypt are widely supported and perfectly adequate for most sites. Paid certificates offer extra validation or warranties that larger organisations sometimes want, but most businesses don't need them.
Will switching to HTTPS affect my Google ranking?
HTTPS is a confirmed Google ranking signal, so it helps. More importantly, it removes the 'Not Secure' warning that scares visitors away, which protects conversions and trust.

Looking for the right provider?

Browse verified, reviewed businesses on UK Web Agency Directory and request quotes in minutes.

Browse the directory →

Keep reading