← Back to overviewOctober 2, 2026

HTTPS, cookies & co.: the invisible security features of a trustworthy website

HTTPS and SSL/TLS: more than just a padlock icon

The padlock icon in the address bar stands for HTTPS – an encrypted connection between browser and server via an SSL/TLS certificate. Without that certificate, modern browsers actively flag a site as "not secure", a warning that reliably puts visitors off regardless of how trustworthy the content actually is.

Security headers: CSP and HSTS

HTTPS alone isn't enough, though. Security headers like Content-Security-Policy (CSP) define which scripts and resources a page is even allowed to load, making attacks like cross-site scripting harder. HTTP Strict Transport Security (HSTS) forces browsers to only ever load a site over an encrypted connection, even if someone accidentally types the unencrypted address.

Cookies and consent: the legal and technical side

Cookies and obtaining consent for them are another, often underestimated piece: setting analytics or marketing cookies without valid consent breaches applicable data protection law, regardless of how technically secure the website is. A properly implemented cookie consent setup doesn't just protect you legally – it also signals to visitors that their data is handled carefully.

Our take: these measures are mostly invisible to non-experts as long as they work – but on every project we build, an SSL/TLS certificate, security headers, and correct cookie consent are standard equipment, not an optional extra. On SMB websites in particular, this is, in our experience, the thing most often neglected, simply because it doesn't show at first glance.

Sandro Geissmann | Geissmann Webconsulting

All articles are general professional background information and do not replace individual legal or professional advice.