Security Basics5 min read29 September 2026

SSL Certificates and Website Security UK — What the Padlock Actually Means

Most UK business owners think the padlock means their website is secure. It doesn't. Here is what an SSL certificate actually protects — and what it doesn't.

By Yrzo AI — UK cybersecurity specialists

The Padlock Myth

Ask most UK small business owners whether their website is secure and they will say yes — because it has a padlock. The padlock in the browser address bar has become the shorthand for "this site is safe." It is not.

The padlock means one thing and one thing only: the connection between your visitor's browser and your web server is encrypted. Data in transit is protected. An attacker eavesdropping on the network cannot read the content of the request or response.

That is genuinely important. But it says nothing about:

- Whether your login form can be bypassed - Whether your database can be accessed through your contact form - Whether an attacker can steal your customers' data through a script injection - Whether your admin panel is protected from brute force - Whether your server is running software with known vulnerabilities

A website can have a valid SSL certificate and be utterly compromised at the application layer. The padlock and the vulnerabilities coexist.

What SSL/TLS Actually Does

SSL stands for Secure Sockets Layer. TLS — Transport Layer Security — is its successor and what is actually in use today, though most people still say SSL. When you see HTTPS in your browser's address bar, TLS is active.

TLS establishes an encrypted tunnel between the browser and the server using a process called the TLS handshake. During the handshake:

1. The server presents its certificate, which contains its public key and is signed by a trusted Certificate Authority (CA) 2. The browser verifies the certificate is valid, has not expired, and was issued for the correct domain 3. A session key is negotiated using asymmetric encryption 4. All subsequent communication is encrypted using that session key

The encryption means that if someone intercepts the traffic — on a public Wi-Fi network, for example — they see only encrypted data, not your customers' passwords or form submissions.

This is meaningful protection. Websites without HTTPS leak user data in plaintext. Google has marked HTTP sites as "Not Secure" since 2018. It also factors into search rankings.

But TLS protects the channel, not the application.

What SSL Does Not Protect Against

**SQL injection** — If your web application does not properly sanitise user input, an attacker can submit crafted SQL through your contact form or search box. The TLS encryption dutifully encrypts and forwards that malicious payload to your server. The database does not know or care that the traffic was encrypted.

**Cross-site scripting** — An attacker who finds an XSS vulnerability can inject malicious JavaScript into your web pages. Your visitors load those pages over HTTPS. The malicious script executes in their browsers anyway.

**Stolen credentials** — If your users' login details are stored as unsalted hashes or in plaintext, a database breach exposes them regardless of SSL. TLS protected the password in transit; nothing protected it at rest.

**Compromised servers** — SSL certificates authenticate your server's identity, not the security of what's running on it. A server running outdated software with known vulnerabilities is a compromised server waiting to happen, HTTPS or not.

**Phishing sites** — Attackers can obtain legitimate SSL certificates for fraudulent domains. A site at `paypai.co.uk` can have a valid padlock. The padlock confirms the connection to that domain is encrypted — not that the domain is trustworthy.

Types of SSL Certificates

Not all SSL certificates are the same, though the padlock looks identical in all cases:

**Domain Validation (DV)** — The cheapest and most common. The CA verifies only that the applicant controls the domain. No identity information is checked. Free certificates from Let's Encrypt are DV certificates. There is nothing wrong with DV certificates — they provide the same encryption as more expensive alternatives.

**Organisation Validation (OV)** — The CA verifies the organisation's existence and legal status in addition to domain control. Provides more assurance that you are dealing with a legitimate business.

**Extended Validation (EV)** — The most rigorous identity checks. Historically displayed a green bar in browsers with the company name — browsers have largely removed this visual distinction, reducing EV's visible benefit.

For most UK small businesses, a DV certificate — including a free Let's Encrypt certificate — is entirely appropriate. The encryption is the same.

Certificate Validity and Expiry

SSL certificates expire. The standard validity period is 90 days for Let's Encrypt certificates and up to one year for paid certificates (two-year certificates were deprecated by the CA/B Forum in 2020).

An expired certificate causes browsers to display a prominent warning rather than the padlock, discouraging visitors and damaging trust. Worse, it indicates that whoever manages the site is not actively maintaining it — not a reassuring signal.

Automated certificate renewal is standard in most modern hosting environments. If you are manually managing certificates, this is a risk worth monitoring.

TLS Version Matters

Not all TLS is equally secure. Older versions have known vulnerabilities:

**SSL 3.0 and TLS 1.0** — Should be disabled. Vulnerable to POODLE, BEAST, and other attacks. Reputable browsers have dropped support for TLS 1.0.

**TLS 1.1** — Deprecated. No longer considered secure.

**TLS 1.2** — Acceptable but being superseded. Still widely used.

**TLS 1.3** — Current standard. Faster handshake, stronger cipher suites, forward secrecy by default. This is what your server should be configured to use.

A server that still accepts TLS 1.0 connections is exposing legacy visitors to attacks that have been known for years. Checking your TLS configuration is part of any serious security assessment.

What Actually Protects Your Website

SSL/TLS is one layer of security. A robust website security posture includes:

- Proper input validation and output encoding to prevent injection attacks - Rate limiting on authentication endpoints - Security headers (Content-Security-Policy, HSTS, X-Frame-Options) - Regular patching of your CMS, plugins, and server software - Strong authentication, including multi-factor authentication for admin access - Security testing to find what you've missed

Yrzo AI's automated security assessments check 44 security controls, including your TLS configuration, cipher suites, security headers, injection vulnerabilities, and authentication weaknesses. The padlock is a starting point. Knowing what's actually secure is something else. Scans start at £99.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →