ResourcesโSSL & Website Security
ResourcesโSSL & Website Security
.๐ SSL & Website Security
Your website is an important part of your business.
It represents your brand, communicates with customers and may collect information such as contact details, enquiries, login information or payments.
Website security therefore shouldn't be treated as an optional extra.
One of the first security measures every website should have is SSL/TLS, which enables HTTPS.
But there's an important difference:
SSL helps protect information travelling between your website and its visitors. It does not protect your entire website from every type of attack.
SSL stands for Secure Sockets Layer.
Today, modern websites generally use its successor, TLS (Transport Layer Security), but the term "SSL certificate" is still commonly used.
An SSL/TLS certificate allows your website to use:
HTTPS://
instead of:
HTTP://
For example:
๐ https://www.yourbusiness.co.za
The padlock shown in a browser indicates that the connection between the visitor's browser and the website is encrypted.
HTTPS helps protect information while it travels between a visitor and your website.
This is particularly important when a website handles:
Contact forms
Login information
Customer information
Passwords
Online payments
Other sensitive information
It also prevents browsers from displaying the old "Not Secure" warning that can appear on websites without HTTPS.
If your website still uses:
http://
instead of:
https://
it's worth investigating why.
This is one of the most important things to understand.
An SSL/TLS certificate helps secure the connection between the visitor and the website.
It does not automatically protect your website from:
Hacking
Malware
Weak passwords
Outdated software
Vulnerable plugins
Compromised user accounts
Website code vulnerabilities
Poor hosting security
Phishing
Other cyber threats
Think of SSL as one layer of protection, not the entire security system.
A secure website should ideally have several layers of protection.
Protects data travelling between the visitor and the website.
Use strong, unique passwords for hosting, website administration and email.
Keep your website platform, themes, plugins and other software updated.
Maintain reliable backups so your website can be restored if something goes wrong.
Use appropriate security tools to detect and help prevent malicious activity.
Only give people the access they actually need.
Where appropriate, monitor your website for suspicious activity, downtime or security problems.
The easiest way is to open your website in a browser.
Look at the address bar.
A secure website should normally begin with:
https://
You may also see a padlock or other security indicator depending on the browser.
For example:
๐ https://yourbusiness.co.za
Don't rely only on the padlock.
A website can have HTTPS and still contain security problems or malicious content.
Not necessarily.
Many hosting providers now include SSL certificates with their hosting packages.
Some use free certificates such as Let's Encrypt, while other providers offer paid certificate options.
For many small-business websites, a properly configured free SSL certificate may be perfectly adequate.
Don't automatically pay for an SSL certificate just because someone tells you that you need one.
First check whether your hosting provider already includes SSL.
Different websites have different requirements.
Businesses with more complex security, compliance or validation requirements may consider paid certificate options.
For example, larger organisations or websites with particular security and validation requirements may want additional certificate features or warranties.
For a typical small-business website, however, free SSL may be sufficient.
The important thing is that HTTPS is properly installed and working.
A website without HTTPS can create several problems.
Visitors may see security warnings.
Some browsers may display:
Not Secure
Visitors may also be less comfortable entering information into forms.
And if your website accepts passwords or other sensitive information, sending that information over an unsecured connection can expose it to interception.
After SSL has been installed, your website should normally redirect visitors from:
http://yourbusiness.co.za
to:
https://yourbusiness.co.za
This helps ensure visitors consistently use the secure version.
Your website should also avoid having some pages load securely while others still use HTTP.
This is commonly referred to as mixed content and can create security warnings or prevent some resources from loading correctly.
Imagine spending months building your website and then losing it because of:
A technical problem
A hacking incident
A faulty update
Human error
Server failure
That's why reliable backups are important.
Before choosing hosting, check:
Does the provider include backups?
And if backups are included, check:
How frequently are they made?
How long are they retained?
Can you restore the website yourself?
Are databases included?
Are backups stored separately?
A backup is only useful if you can actually restore it.
Your website security is only as strong as the accounts controlling it.
Use:
Strong passwords
Unique passwords
Two-factor authentication where available
Secure password storage
Separate accounts for different users where appropriate
Never share your main administrator password with everyone who works on your website.
If your website uses a platform such as WordPress, outdated software can create security risks.
Keep your:
WordPress installation
Themes
Plugins
Extensions
Server software
up to date where appropriate.
Don't blindly update everything on a live website without considering compatibility.
For important websites, make sure you have a reliable backup before making significant updates.
Depending on your website, you may also want to consider:
Can help filter malicious traffic before it reaches your website.
Can help identify malicious code or suspicious files.
Can help protect against certain types of traffic attacks.
Useful for contact forms and comments.
Can help prevent repeated attempts to gain access.
Can alert you to certain changes or suspicious activity.
Not every website needs every security product.
Let's Encrypt provides free SSL/TLS certificates and is widely used to enable HTTPS on websites.
Good for:
Website owners and hosting providers looking for free SSL/TLS certificates.
Cloudflare provides a range of website performance and security services, including DNS, CDN and security features.
Good for:
Businesses wanting additional website performance and security services.
Your hosting provider may already include SSL, backups and other security features.
Before purchasing additional services, check what is already included with your hosting package.
AgencyOS Tip:
This is one reason we recommend comparing hosting providers carefully.
Before considering your website secure, check:
โ HTTPS is working
โ SSL/TLS certificate is valid
โ HTTP redirects to HTTPS
โ Website software is updated
โ Strong administrator passwords are being used
โ Two-factor authentication is enabled where available
โ Reliable backups are available
โ Contact forms have spam protection
โ Hosting security features are enabled
โ Unnecessary plugins and accounts have been removed
โ Website access is limited to people who need it
Security is not a once-off job.
Your website can be secure today and become vulnerable later because of an outdated plugin, compromised password, new software vulnerability or other change.
Treat website security as an ongoing part of website maintenance.
If you receive an email saying:
"Your SSL certificate is about to expire โ click here immediately."
Don't automatically click the link.
Scammers sometimes use fake SSL-renewal warnings to steal login details or install malware.
Instead, log into your hosting provider or website platform directly and check the certificate status.
Let's Encrypt
Free SSL/TLS certificates.
Cloudflare
Website performance, DNS and security services.
Your Hosting Provider
Check whether SSL, backups and security features are already included.
Some links on this page may be affiliate links. If you purchase a product or service through one of our affiliate links, AgencyOS may receive a commission at no additional cost to you.
We aim to recommend resources based on their usefulness, features and suitability for small businesses.
HTTPS is essential. SSL is important. But website security goes much further than the padlock in your browser.
A secure website combines SSL/TLS, strong passwords, updates, backups, secure hosting and ongoing monitoring.