What is it?
Why is it important?
Are you breaking the law without it?
Spoiler alert! Yes, you're breaking the law without a secure website.
Join Our Facebook Group: https://bit.ly/PropertyGroup
Full Blog Post: https://www.2waydigital.com/website-s...
Video Script:
To protect your clients and visitors data while they are on your website, you need to make sure your website is using https. The way you do this is to use an SSL certificate.
What does HTTPS mean?
https in the address bar
HTTPS stands for Hypertext Transfer Protocol Secure
BUT WHAT DOES IT MEAN?
Yeah! We know, gobbledygook…
Simply put, when you access a website using HTTPS, everything gets encrypted between the user and the website. Here is a diagram to help understand:
HTTPS with SSL Encryption Explained
You might be thinking:
“How does this affect me, I don’t even collect data on my website?”.
GDPR (Data Protection Act 2018)
GDPR made a point of saying that it is the responsibility of business owners to make sure that customers and visitors data is secure.
The ONLY way to do this is to make sure ALL communication on your website is secure.
The easiest way to do this is to add an SSL certificate to your website and make sure you use HTTPS.
A Ranking Factor Since 2014
Google's 2014 Pidgeon Update
Google considers it important enough that they included HTTPS as a ranking factor in the 2014 Pidgeon updates.
While it may not have been given any more weight in recent years, it still means that your rankings will very likely be penalised by Google if you are not using a secure website.
There Are No Excuses
There is really no reason not to have SSL on your website since it costs you nothing to implement it.
Since Let’s Encrypt was set up at the end of 2014, there has not been a need to pay ridiculous prices for SSL certificates.
Let’s Encrypt Certificates are completely free, forever.
Let’s Encrypt is a non-profit certificate authority run by the Internet Security Research Group (ISRG) that provides certificates for encryption at no charge.
Get started here:
Let’s Encrypt have been doing a lot of work over the years to work with website hosting companies to integrate their certificates into the back end.
This means many hosts (maybe yours) have an easy “Click to Install an SSL certificate” on your website.
Check the list of Web Hosts who have integrated Let’s Encrypt here:
Web Hosts with Let’s Encrypt Support
Check to see if this is available to you before you start trying to manually add a certificate with shell access.
⭐TimeOut⭐
Oh! And if the “reason” we put above for you not currently having SSL on your website
I don’t even collect data on my website
is actually the reason your website doesn’t already have SSL, that isn’t your only problem that needs fixing.
Your website should be a lead generating machine which means you need ways to collect visitor and lead data
but…
that’s another story.
⭐End of TimeOut⭐
Back to the business at hand. When you have got your SSL setup, either by:
Using the integrated Let’s Encrypt Tool
Contacting your website host support team for help
Installing the SSL Certificate manually
Googling {How to Setup SSL on “MyHost”, “MyPlatform”}
Talking to your Webmaster
Or posting in our Facebook Group to get some help
You’ll be a step closer to being fully compliant with UK law regarding privacy.
The trust of people visiting your website will increase.
You’ll be able to collect potential lead data safely.
Final Check
The Final Check
Hopefully, you had nothing to do in this lesson.
If you did, check the permanent redirect (301) is working okay both with and without www.
You need to do a quick test to make sure you also got a permanent redirect (301) from HTTP to HTTPS. If there is any automation provided by your host for SSL, the redirect may be automatic.
How To Test
Simply type the full address of your website into a browser but don’t add the {S} onto HTTP.
Type your full address into your browser with http:// like this:
Example: http://2waydigital.com
The 301 redirects should engage and
Automatically Go To
Check that http://www.yourdomain.com also redirects to https.
If this does not happen, then your next step is to set up the 301 redirect or check on your configuration if you’ve already manually tried to install your certificate.
We use a 301 Redirect and not a 302 because if your existing HTTP domain has built up any authority, this gets transferred (mostly) to the new secure site. [More on that in another post]
If you have questions, queries, uncertainty or any other form of doubt, feel free to ask in the comments below or join our Facebook Group.