Somebody has already paid for an SSL certificate on your website. You were shown a padlock and told the site was secure, and nobody explained what the padlock means. That gap between what people believe it means and what it does is where most of the real risk sits. An installer sending a quotation, a shop taking card payments, a business emailing an accountant abroad, all on connections somebody has called protected. The claim is usually true and almost always incomplete.
What an SSL certificate actually proves
The name is out of date. The protocol underneath the padlock is TLS, and the file is a public key certificate: a public key, a statement about who that key belongs to, and a digital signature from a certificate authority. The browser checks that a trusted authority signed it and that the name inside matches the address you typed, and the conversation is then encrypted. The mechanics are in the public key certificate reference, and the settings that matter in practice are in the OWASP transport layer security cheat sheet.
Read that promise carefully, because it is narrower than most people assume. It is a promise about the connection, not the website. The bytes travelling in both directions cannot be read or changed by somebody in the middle, and this server holds this domain name. It says nothing about who runs the server, whether the site has been hacked, or whether the person writing to you is honest.
Trust runs back along a chain rather than standing on the file itself. It starts at the certificate on your server, passes through one or more intermediate certificates the authority issued, and ends at a root certificate already inside your browser or operating system. That root is the trust anchor and is deliberately hard to change, which is why the chain must be complete. An incomplete chain is the commonest reason a site works in one browser and warns in another: the leaf certificate was installed and the intermediate was not.
There are three levels of checking. Domain validation only confirms you can administrate the domain, usually by answering a challenge at a well-known web address, and that is what Let’s Encrypt, a free non-profit authority, issues. Organisation validation adds checks on the legal entity, and extended validation adds manual document review. Extended certificates once displayed a green bar with the company name; Chrome and Firefox removed that in 2019 after researchers showed how easily such certificates had been bought to impersonate famous organisations. Nobody sensible needs one for a small business site.
What the padlock does not protect you from
Here is the honest conversation. A valid certificate protects a connection in transit, and nothing else. It does not protect a WordPress site with an outdated plugin, the commonest real cause of a small business site being defaced or turned into a spam relay, and it does not protect an administrator who installs whatever they were emailed a link to download.
It also does not protect you from being phished into handing over a password. If an attacker convinces you to type your banking password into a page they control, the connection to that page can be perfectly encrypted and correctly certified. The padlock is honest about who you are talking to, and the person you are talking to is the attacker. Email security and phishing covers that sequence, and the cyber attack chain places it in a larger intrusion.
A further limit applies to a business running its own wireless network. A certificate protects the link between one device and one server, not the access point, and on a shared network every device sits on the same segment unless somebody separated them. That is why router security matters as much as the padlock.
Free versus paid certificates
For a normal website a free domain-validated certificate from a well-known non-profit authority is enough. Let’s Encrypt states plainly that it charges no fee, never stores your private key, and issues only domain-validated certificates because the other two cannot be automated. A paid product adds automation, managed renewals and cover.
| Option | What it proves | Cost and lifetime | Worth it for |
|---|---|---|---|
| Free domain-validated, auto renewal | You control the domain name | No fee, 90 days, automatic | Almost every small business site |
| Paid domain-validated, managed | You control the domain name | Annual fee, multi-year, support included | Sites where downtime is expensive |
| Paid organisation-validated | Domain control plus entity checks | Annual fee, more paperwork | Corporate counterparty checks |
| Paid extended validation | Domain control plus identity review | Annual fee, the highest | Rarely, for ordinary businesses |
One detail about the free route surprises people. The 90-day lifetime is deliberate. Let’s Encrypt has published a lifetime rationale explaining that short lifetimes limit the damage from a mis-issued or stolen key and force renewal to be automated. A 90-day certificate is not a sign of a second-class product. It is a sign that renewal has to be a machine’s job, not a human remembering a date.
Mixed content, the error that undoes the padlock
A browser will show a padlock and still block part of the page. This happens when an HTTPS page tries to load something over plain HTTP: a script, an image, a font, a video. The secure parts load, the insecure parts do not, and the warning says the site is not fully secure. The cause is nearly always a plugin, a theme asset, an embedded map or a custom snippet holding a hard-coded http:// address, or an image pasted in from a plain HTTP result.
It matters more than a cosmetic annoyance. An attacker on an untrusted network can alter the insecure part, and if that part is a script they have injected code into a page you believe is protected. That is the argument for turning one on when doing anything sensitive on shared public wifi. On your own site the fix is unglamorous: find the offending request in the browser developer tools, find the plugin or theme setting behind it, and replace the address.
The renewal failure that takes a site down
Here is a pattern we see repeatedly. The site goes quiet for a few days, customers message that it is down, and nobody has touched anything. The certificate expired. On a free automated setup renewal depends on a scheduled task on the server, and that task can be removed by an update, a migration to a new host, a cleanup plugin, or a developer tidying cron jobs. A paid setup fails the same way when the renewal card has expired or the domain was not renewed.
Certificate management is an operations problem, not a purchase. Set calendar reminders at half the lifetime and again a fortnight before expiry. Keep the hosting account and registrar contact details current, because the renewal notice goes to an address that may belong to somebody who has left. And test that the site loads over https, not merely that a padlock appears, from a phone on mobile data rather than the office. A site offline for a week is a business continuity problem before a security one, which is the argument in ransomware preparation for small businesses.
A practical checklist for a small business
You do not need the cryptography to get this right. Open the site on a phone using mobile data and confirm the address bar shows https with no insecure-item warning. Check the expiry date in the connection information. Confirm that logins and payments land on a page whose domain is exactly your business domain. Then ask the provider three questions in writing: who holds the account, what happens on expiry, and is renewal automatic. An answer you cannot get in writing is not an answer. A certified site is still one click from disaster if whoever can reset the email password uses one password everywhere, which is the argument in password security for 2026.
Frequently asked questions
Is a free SSL certificate as good as a paid one?
For encryption, yes. A Let’s Encrypt certificate and a paid one use the same machinery, so the traffic is protected to the same standard. What you give up is convenience and support: renewal is automatic only if the automation is set up and still working, there is nobody to ring, and you do not get the higher validation levels. The real question is whether anybody owns the renewal process.
Why does my browser warn about a site that has one?
The commonest causes are an incomplete chain of trust, a hostname that does not match what is inside, and expiry. Less common but worth knowing is a device whose clock is wrong, because validity is checked against the time. A fourth is an older certificate relying on the legacy common name field, which Chrome stopped checking in 2017 in favour of the alternative name list.
Does an SSL certificate protect my website from being hacked?
No, and anyone who says otherwise is selling you something. Hacking usually happens because of a vulnerable plugin, a weak password on the hosting account, an exposed file or a stale content management system, none of which a padlock touches. If your site is a target, the fixes that matter are credential hygiene and patching.
Why do I need one for every subdomain?
A standard certificate covers a single hostname. One certificate can list several hostnames in its alternative name field, and a wildcard covers a whole level of subdomains, which is convenient when you run a shop, a blog and a booking page. The trap is that a wildcard covers one level only: it matches shop.example.com but not booking.shop.example.com, and not the bare example.com. Decide the list before you buy.
Key Takeaways
- An SSL certificate proves two things: the connection is encrypted, and the server holds the domain name. Nothing about who runs the site.
- It does not stop phishing or a compromised server. Credentials typed into a fake page are still credentials handed over.
- A free domain-validated certificate is enough for almost every small business site. Pay for managed renewal, not a bigger padlock.
- Free ones last 90 days by design, so renewal is automated. If that job dies, the site goes offline and nobody is looking.
- Mixed content means part of a supposedly protected page is not. Find the http address and replace it.
- Renewal dates and account ownership belong in a maintenance routine, not in memory.
The next layer down decides most account compromises: email security and how to spot phishing.
Sources: Let’s Encrypt frequently asked questions and service details; Let’s Encrypt lifetime rationale and plans; chain of trust, validation levels and browser trust stores; OWASP transport layer security cheat sheet.
0 Comments