HTTPS is the secure, encrypted version of a web address, the one a browser marks with a small padlock, so that information passing between a visitor and your site cannot be read or altered along the way. The older, unencrypted version is plain HTTP, with no padlock.
For a small business, HTTPS is the quiet baseline of looking legitimate. Browsers now flag pages without it as “Not secure,” a warning that can stop a first-time visitor before they read a word, and Google has said it counts HTTPS as a small ranking factor. The padlock comes from an SSL certificate, a piece of proof that your site is what it claims to be; the certificate is what the browser checks before it shows the lock.
Every site I build serves only over HTTPS, with the certificate set up and renewing on its own, so visitors never meet a security warning and the encrypted version is the only one that loads. It is also one of the plain boxes a technical SEO check looks for, because a secure connection is one of the basics search engines expect before they trust a page.