If your website URL starts with “http://” instead of “https://”, you’re losing customers, hurting your search rankings, and leaving your site vulnerable to attacks. The fix is simple and usually free, but many Sydney businesses still haven’t made the switch.
Here’s what HTTPS actually does, why it matters for your business, and how to implement it properly.
What HTTPS Actually Does
HTTPS stands for “Hypertext Transfer Protocol Secure”. The “S” is the important part. It means data travelling between your website and your visitors is encrypted.
Without HTTPS, data travels in plain text. Anyone intercepting the connection (your internet service provider, someone on the same public WiFi network, or a malicious hacker) can read everything: form submissions, passwords, credit card details, emails, login credentials.
With HTTPS, that data is encrypted. Even if someone intercepts it, they can’t read it without the encryption key.
How It Works
HTTPS uses SSL/TLS certificates to encrypt the connection. When someone visits your website, their browser checks your SSL certificate, verifies it’s legitimate, and then establishes an encrypted connection.
This happens automatically in milliseconds. Visitors don’t need to do anything, and most won’t even notice it’s happening. They just see a padlock icon in the address bar and “https://” in the URL.
What Gets Encrypted
Everything transmitted between the visitor and your server:
- Contact form submissions
- Login credentials
- Payment information
- Personal details (names, addresses, phone numbers)
- Email addresses
- Session data (what pages they visit, what they click on)
Even if you don’t handle sensitive data like credit cards, HTTPS still matters. Email addresses submitted through contact forms are valuable to spammers. Session data can be used to track users without their consent. And Google cares about HTTPS for ranking purposes.
Google Ranking Impact
Google has been pushing HTTPS since 2014, and the pressure has increased every year. Here’s what the data shows.
HTTPS Is a Ranking Signal
Google confirmed in 2014 that HTTPS is a ranking factor. Sites with HTTPS get a small ranking boost over identical sites without it.
The boost is small (Google estimated it affects less than 1% of global queries), but in competitive markets, that 1% can be the difference between ranking on page one or page two.
Studies by Moz and Backlinko found that 95% of page one Google results use HTTPS. That correlation isn’t proof that HTTPS directly causes better rankings, but it’s clear that sites ranking well have made the switch.
Chrome Labels HTTP Sites as “Not Secure”
Since 2018, Google Chrome (which has 65% of the browser market) displays a “Not Secure” warning for HTTP sites. This warning appears in the address bar, right next to your domain name.
When potential customers see “Not Secure” next to your business name, they trust you less. Many will leave immediately, especially if you’re asking them to fill out a form or make a purchase.
A study by GlobalSign found that 84% of users would abandon a purchase if they knew the site wasn’t secure. Even if your site doesn’t actually have security issues, the warning is enough to scare people away.
Other Browsers Follow Chrome’s Lead
Firefox shows similar warnings. Safari highlights HTTPS sites with a positive indicator and shows nothing for HTTP sites, which creates a trust gap.
Edge (Microsoft’s browser) also warns users about HTTP sites, especially if forms are present on the page.
Across all browsers, the message is clear: HTTPS is the standard, and HTTP is being phased out.
Real Impact Example
A Sydney law firm switched from HTTP to HTTPS in 2023. Their search rankings didn’t change dramatically overnight, but they saw a 12% increase in organic traffic over 3 months. More importantly, their form submission rate increased by 19% because visitors no longer saw the “Not Secure” warning.
That 19% increase translated to 4-5 extra client enquiries per month, which more than paid for the time and cost of implementing HTTPS.
Browser Warnings Without HTTPS
Let’s look at exactly what visitors see when they visit an HTTP site in different browsers.
Google Chrome
Chrome displays “Not Secure” in grey text to the left of the URL. If the site has a form (contact form, newsletter signup, login), Chrome makes the warning more prominent.
When a user clicks into a form field on an HTTP site, Chrome shows a popup warning: “Your connection to this site is not secure. You should not enter any sensitive information on this site (for example, passwords or credit cards), because it could be stolen by attackers.”
That’s not subtle. It’s a clear message that your site isn’t safe.
Firefox
Firefox shows a grey padlock with a red strike-through for HTTP sites. Clicking the icon shows a warning: “Connection is not secure. Logins entered here could be compromised.”
Like Chrome, Firefox becomes more aggressive if there’s a form on the page.
Safari
Safari is less aggressive. It doesn’t show a warning for HTTP sites, but it does show a green padlock for HTTPS sites. The absence of the padlock signals to informed users that the connection isn’t secure.
Edge
Microsoft Edge shows “Not secure” in the address bar for HTTP sites, similar to Chrome.
What This Means for Your Business
Most visitors won’t consciously think “this site doesn’t have HTTPS”. But they’ll see the “Not Secure” warning and feel uneasy. That unease translates to lower conversion rates, fewer form submissions, and higher bounce rates.
Your competitors who have HTTPS don’t have this problem. All else being equal, visitors will choose the secure site over the insecure one.
SSL Certificate Types and Costs
There are three main types of SSL certificates, and the one you need depends on your website and business type.
Domain Validation (DV) Certificates
DV certificates verify that you control the domain. The certificate authority (CA) checks that you can receive email at the domain or add a specific DNS record, and if you can, they issue the certificate.
This process is automated and takes minutes. DV certificates are what most small businesses need.
Cost: Free (via Let’s Encrypt) to $50 per year from commercial providers.
Best for: Small business websites, blogs, brochure sites, most WordPress sites.
Organisation Validation (OV) Certificates
OV certificates include verification of your business identity. The CA checks that your business is registered, that you’re authorised to represent it, and that the details in the certificate match your business registration.
This process takes 1-3 days and involves submitting business registration documents.
Cost: $50-$150 per year.
Best for: Businesses that want to show extra credibility, government websites, organisations handling sensitive data.
Extended Validation (EV) Certificates
EV certificates involve the most rigorous verification. The CA conducts a thorough background check on your business, including physical address verification, phone verification, and checks against government databases.
In older browsers, EV certificates displayed your company name in green in the address bar. Modern browsers removed this feature in 2019-2020, which reduced the visible benefit of EV certificates.
Cost: $150-$400 per year.
Best for: Large e-commerce sites, banks, financial institutions. Most businesses don’t need this level of validation anymore.
Wildcard Certificates
Wildcard certificates secure your main domain and all subdomains (like blog.yourdomain.com, shop.yourdomain.com, etc.) with one certificate.
Cost: Free (via Let’s Encrypt) to $100-$300 per year from commercial providers.
Best for: Businesses with multiple subdomains.
What Most Businesses Should Use
For 95% of Australian businesses, a free Let’s Encrypt DV certificate is perfectly sufficient. It provides the same encryption as expensive certificates, it’s trusted by all browsers, and it renews automatically.
The only reasons to pay for a certificate are:
- You want phone support from the certificate provider
- You need warranty coverage (some paid certificates include financial guarantees)
- You require OV or EV validation for regulatory compliance
If none of those apply, use Let’s Encrypt and save the money.
How to Implement HTTPS
Switching from HTTP to HTTPS isn’t complicated, but you need to do it properly to avoid breaking your site or losing search rankings.
Here’s the process.
Step 1: Get an SSL Certificate
Most Australian web hosts now include free SSL certificates (via Let’s Encrypt) with hosting plans. Check your hosting control panel (cPanel, Plesk, or your host’s custom panel) for an SSL section.
If your host offers free SSL, you can usually install it with one click. The certificate will auto-renew every 90 days.
If your host doesn’t offer free SSL (time to find a better host), you can purchase a certificate from providers like Comodo, DigiCert, or Sectigo for $50-$150 per year. Your host should have instructions for installing purchased certificates.
Step 2: Install the Certificate
This step varies by host, but most make it simple:
- cPanel: Go to Security > SSL/TLS Status, select your domain, click “Run AutoSSL”
- Plesk: Go to Websites & Domains > your domain > SSL/TLS Certificates > Install
- Custom panels: Look for SSL, HTTPS, or Security sections
If you’re on a managed WordPress host (WP Engine, Kinsta, Flywheel), they handle SSL automatically. Just enable it in your dashboard.
Step 3: Update Your Site to Use HTTPS
Installing the certificate doesn’t automatically switch your site to HTTPS. You need to update your WordPress settings (or site configuration if you’re not using WordPress).
For WordPress:
- Go to Settings > General
- Change “WordPress Address (URL)” from http://yourdomain.com to https://yourdomain.com
- Change “Site Address (URL)” from http://yourdomain.com to https://yourdomain.com
- Save changes
For non-WordPress sites, you’ll need to update your site configuration file or ask your developer to do it.
Step 4: Set Up 301 Redirects
This is critical. You need to redirect all HTTP traffic to HTTPS automatically, so visitors typing “http://yourdomain.com” are sent to “https://yourdomain.com”.
Without redirects, you’ll have duplicate content (Google sees the HTTP and HTTPS versions as separate sites), and some visitors will still access the insecure version.
For WordPress, use a plugin like Really Simple SSL to handle redirects automatically.
For other sites, add this code to your .htaccess file (if you’re on Apache servers):
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
If you’re on Nginx servers, the redirect code is different. Ask your host or developer for help.
Step 5: Update Internal Links
Go through your site and update any hardcoded HTTP links to HTTPS. This includes:
- Links in your navigation menu
- Links in page content
- Image URLs
- Script and stylesheet URLs
For WordPress, plugins like Better Search Replace can find and replace all HTTP URLs with HTTPS in your database.
Alternatively, use relative URLs (like “/about” instead of “http://yourdomain.com/about”) so links work regardless of protocol.
Step 6: Update External Services
If your site integrates with external services, update those too:
- Google Analytics: Update your property URL
- Google Search Console: Add the HTTPS version as a new property
- Social media profiles: Update your website links
- Email signatures: Update your website link
- Advertising campaigns: Update landing page URLs
Step 7: Test Everything
Visit your site using HTTPS and check that:
- All pages load correctly
- Images display properly
- Forms still work
- External scripts and integrations function
- You see a padlock icon in the address bar
Use a tool like Why No Padlock to check for mixed content errors (where some resources still load via HTTP instead of HTTPS).
Step 8: Monitor for Issues
After migrating to HTTPS, watch your analytics for traffic drops or error spikes. Check Google Search Console for crawl errors.
Most properly executed HTTPS migrations have no negative impact. If traffic drops significantly, you’ve probably got a redirect issue or mixed content errors.
Common HTTPS Migration Mistakes
Here are the mistakes businesses make when switching to HTTPS, and how to avoid them.
Not Setting Up 301 Redirects
If you enable HTTPS but don’t redirect HTTP traffic, you’ll end up with two versions of your site competing in search results. Google might continue ranking the HTTP version, which means visitors will see “Not Secure” warnings even though you’ve installed SSL.
Always set up 301 redirects from HTTP to HTTPS.
Forgetting to Update Google Search Console
Google treats HTTP and HTTPS as separate sites. You need to add the HTTPS version as a new property in Search Console and submit a new sitemap.
If you don’t, Google won’t know to crawl and index the HTTPS version, and your rankings could suffer.
Mixed Content Errors
Mixed content happens when your page loads via HTTPS, but some resources (images, scripts, stylesheets) load via HTTP. Browsers will block these resources or show a warning, which breaks your site’s functionality.
Check for mixed content using browser developer tools (press F12, look for warnings in the console) or online tools like Why No Padlock.
Not Updating Hardcoded Links
If your content includes links like “Visit http://yourdomain.com/services”, those links will redirect to HTTPS, but it’s an extra hop that slows things down and looks unprofessional.
Update all internal links to HTTPS or use relative URLs.
Letting Certificates Expire
SSL certificates expire after a certain period (90 days for Let’s Encrypt, 1-2 years for paid certificates). If your certificate expires, browsers will show a big scary warning and prevent visitors from accessing your site.
Most hosts auto-renew Let’s Encrypt certificates. If you’re using a paid certificate, set calendar reminders to renew at least 30 days before expiry.
Not Testing Before Going Live
Test HTTPS on a staging site or development environment before switching your live site. This catches issues before they affect real visitors.
How Much Does HTTPS Actually Cost?
For most businesses: $0.
Let’s Encrypt provides free SSL certificates that are just as secure and trusted as paid certificates. Most Australian web hosts include Let’s Encrypt integration, so enabling SSL is literally a one-click process.
If you want a paid certificate:
- DV certificate: $20-$50 per year
- OV certificate: $50-$150 per year
- EV certificate: $150-$400 per year
- Wildcard certificate: $100-$300 per year
If you need help with the migration, web developers charge $100-$300 for a simple HTTPS migration on a small site, or $300-$800 for larger or more complex sites.
What Happens If You Don’t Use HTTPS?
You’ll survive, but you’ll pay a price:
Lower Search Rankings
Google gives preference to HTTPS sites. Your competitors with HTTPS will outrank you, all else being equal.
Browser Warnings Scare Away Visitors
The “Not Secure” warning in Chrome (and other browsers) reduces trust and increases bounce rates. Fewer visitors means fewer leads and sales.
Vulnerable to Attacks
Without encryption, your site is vulnerable to man-in-the-middle attacks where someone intercepts traffic between your site and visitors. This is especially risky on public WiFi networks.
Can’t Use Modern Web Features
Many newer web features (like service workers, geolocation APIs, and progressive web app capabilities) require HTTPS. If you want to use these features in the future, you’ll need HTTPS anyway.
Looks Unprofessional
In 2026, not having HTTPS looks careless. It signals that you’re not paying attention to basic web standards, which makes customers wonder what else you’re neglecting.
Final Thoughts
HTTPS isn’t optional anymore. It’s the standard for all websites, and the benefits (better rankings, increased trust, improved security) far outweigh the minimal cost and effort required to implement it.
Most Sydney businesses can switch to HTTPS for free in under an hour. If you’re not technical, a web developer can handle it in 1-2 hours for $100-$300.
Don’t wait. Every day you run an HTTP site, you’re losing visitors to the “Not Secure” warning and potentially losing ranking positions to competitors who’ve made the switch.
Need help migrating your site to HTTPS? Sites By Design can handle the entire process, from installing the SSL certificate to setting up redirects and testing everything. Get in touch and we’ll get your site secure.