Chase Boulay · August 23, 2026

That 'Not Secure' Warning Is Scaring Away Your Customers

I walked into a shop in Cranston last month. Nice place, been open for years, steady foot traffic. The owner pulled up their website to show me something and right there in the browser bar, in big gray text: Not Secure.

He had no idea it was there. He built the site years ago, it loaded fine, it had his phone number and hours. What was the problem?

Here's the problem: every single person who visited that site on Chrome, Firefox, or Safari saw that warning. And a lot of them left.

What That Warning Actually Means

Your website address starts with either http:// or https://. That "s" stands for secure. It means the connection between your site and the person visiting it is encrypted.

When there's no "s," the connection is open. In theory, someone could intercept data moving between your site and the visitor. For most small business websites that don't take payments directly, the actual risk is pretty low. But browsers don't know that. They just see no encryption and flag it.

So Chrome puts up that "Not Secure" label. On mobile, it can appear as a warning page before someone even reaches your site. You're one extra click away from losing them entirely.

This isn't new, either. Google started pushing HTTPS hard back in 2018. It's been eight years. I still see Rhode Island business websites running on plain HTTP in 2026, and honestly it's wild, because the fix is free.

People See It and Assume the Worst

Here's something most people don't realize: your customers don't know what SSL or HTTPS means. They don't need to. They just see "Not Secure" and their brain fills in the blank.

They think their information is going to get stolen. They think the site is fake. They think you don't know what you're doing.

None of that is fair. But it's what happens. Trust is the whole game when someone lands on your site for the first time. They don't know you. They're deciding in about ten seconds whether you're worth their time. A "Not Secure" warning in the browser bar is a hard strike against you before you've said a word.

I've written about the signals that build or destroy trust on a small business website. This is one of the most visible ones, and it's the easiest to fix.

Google Uses HTTPS as a Ranking Signal

Most people don't know this, but Google confirmed years ago that HTTPS is a ranking factor. It's not the biggest one. Good content and a fast, mobile-friendly site matter more. But if you're competing against another business in Warwick or Pawtucket and everything else is roughly equal, the one with HTTPS gets the nudge.

More importantly, Google is less likely to prominently surface sites that could harm users. A site flagged as insecure is not a site Google wants to send traffic to.

If you want to understand more about how Google actually evaluates your site, I wrote a breakdown of what SEO actually means for a small business. But for today, just know that HTTPS is table stakes. You need it to be in the game at all.

SSL Certificates Are Free and Have Been for Years

This is the part that makes me shake my head when I see an unsecured site in 2026.

There's a nonprofit called Let's Encrypt that started handing out free SSL certificates in 2016. Every major hosting provider picked it up. Squarespace includes HTTPS automatically. Shopify does. Cloudflare does. Most shared hosting plans through Bluehost, SiteGround, Namecheap, Hostinger, all of them have a one-click SSL option built right into the dashboard.

For 99% of small business websites, getting an SSL certificate costs nothing. Zero. You're not paying for security. You're paying for someone to turn it on.

The only situation where SSL gets complicated or costs money is if you're running a very specific enterprise setup, which you're probably not. If you own a barbershop in Federal Hill or a nail salon in Providence, your site can be secured for free today.

How to Check If Your Site Has One

Try this right now.

Open a browser, go to your website, and look at the address bar. If your address starts with https:// and there's a small lock icon next to it, you're good. If it says http:// with no "s," or if you see "Not Secure" anywhere near the address bar, your site is not secured.

You can also type your domain into whynopadlock.com. It'll tell you exactly what's missing and whether there are any mixed content issues (that's when a page is technically HTTPS but still loading some images or scripts over HTTP, which can still trigger warnings).

What to do: Go to your website right now and check the address bar. Write down whether it says http or https. If it says http, that's the problem you need to solve this week.

What to Do If Your Site Doesn't Have One

It depends on who's hosting your site.

If you're on a website builder like Squarespace, Wix, or Shopify: log into your account and check the SSL or security settings. Most of these platforms turn it on automatically, but sometimes it needs to be enabled for a custom domain. Look for an SSL toggle in your domain settings.

If you're on shared hosting like Bluehost, Namecheap, or SiteGround: log into your hosting control panel (usually cPanel). Look for an "SSL/TLS" section or a "Let's Encrypt" option. There's usually a button that says "Install" or "Force HTTPS." Click it.

If you're on WordPress: many hosts handle SSL at the server level, so you may just need to install a plugin called "Really Simple SSL" after your host enables the certificate. That plugin handles the redirect from http to https and fixes most mixed content issues automatically.

If you have no idea who hosts your site: go to who.is and type your domain. It'll show you the registrar and often the host. Or check your email for any receipts from a hosting company.

If someone else built your site and manages it: call them today. Ask them to enable HTTPS on your domain. If they try to charge you a lot for this, that's worth questioning. The certificate itself is free.

What to do: Log into wherever your site is hosted. Look for SSL, HTTPS, or security settings. If you can't find it, search "[your hosting company] enable SSL free" and follow their specific guide. Most have a tutorial. If you're stuck, reach out and I'll point you in the right direction.

One More Thing to Check After You Turn It On

After you enable SSL, make sure your site actually redirects from HTTP to HTTPS. This is called a "force redirect" or "HTTPS redirect."

Without it, someone who types yourbusiness.com without the https:// might still land on the unsecured version. The redirect makes sure any old links, any bookmarks, any Google result that still points to the http version, all of it gets automatically sent to the secure version.

Most one-click SSL setups include this redirect automatically. But it's worth double-checking. Type http://yourdomain.com in the browser and watch what happens. If it redirects to https://yourdomain.com, you're set. If it just loads the http version, you need to enable the redirect separately.

Your hosting control panel usually has a "Force HTTPS" checkbox. Turn it on.

This Is a Basic Expectation Now, Not a Bonus Feature

I want to be straight with you. HTTPS is not going to transform your business on its own. It's not a marketing strategy. Having it isn't going to suddenly bring in new customers.

But not having it is actively costing you. Every person who sees that "Not Secure" warning and bounces is a real person who was already on your site, already considering you, and then left because your site gave them a reason to doubt you.

It's the same thing I see with sites that aren't built for mobile. The site exists, it has information, but something about it signals that it's behind the times. And behind the times reads as untrustworthy.

In 2026, HTTPS is the floor. It's what a basic, functional website looks like. The certificate is free. The fix usually takes under an hour. There's no reason to leave that "Not Secure" label sitting there.

I still walk into businesses in Providence and Warwick where the owner has no idea their site has this warning on it. They think the site is fine because it loads. But what their customers see is different from what they see.

The Bottom Line

If your site says "Not Secure," people leave. Google notices. And the fix is free. Log in to wherever your site is hosted, find the SSL settings, and turn it on. If you don't know how to do that, or if someone built your site and you don't have access, this is worth a phone call today.

A good website builds trust the moment someone lands on it. The "Not Secure" warning does the opposite, before a visitor has even read a single word about your business. Fix it, then focus on the things that actually move people to call you.

Want to Know How Your Site Actually Looks to Customers?

I'll pull up your site, check for SSL issues, and give you a straight read on what's working and what's not. No pitch, just an honest look.

Get a Free Mockup

Not ready yet? Get your free website score in 60 seconds →

Keep Reading