HTTPS is necessary. Without it, browsers warn visitors and some customer data can travel in a form that is easier to intercept. Many owners stop there and assume the rest of the site is in good shape.
Encryption in transit does not fix an old plugin, a public backup file, a weak administrator password, or a customer portal that shows the wrong person’s invoices. Those problems sit behind the padlock.
Treat HTTPS as a baseline, then review the software, access, and settings on the site itself.
