In October 2025, Google announced that Chrome will turn on "Always Use Secure Connections" by default. Starting in 2026, the browser will show a warning before loading a public site that still uses plain HTTP instead of the encrypted HTTPS. The rollout is staged, reaching more protected users first and then all users by late 2026, but the direction is settled: HTTP is being treated as unsafe by default.
The reason is straightforward. On an unencrypted connection, someone in the middle can read or tamper with what loads, injecting malware or a fake page. HTTPS closes that gap.
For a small or mid-size business, this is a simple checklist item you shouldn't ignore. Confirm your website has a valid SSL certificate, that every page loads over https, and that old http links redirect properly. Most hosts include a free certificate now, so there's little excuse. A visitor who hits a "not secure" warning before your homepage even loads is a visitor you've likely already lost.
Further reading: original source ↗
Want this handled for you?
This is exactly the kind of thing our website security work takes off your plate. Start with a free, no-pressure look at your site.
Come aboard