I see now you also have ssl, this is good. But I think all http must be forced to https
Do you know http://cloudflare.com/? This is very easy for setting up and for making things like this, and can help with security and page caching also. Just make free account and set up in only 5 or 10 minutes
Forced HTTPS would be good.
They did try forced https for a little bit and it didn't work very well. However, I do think cloudflare could help no only with the secure aspect, but content delivery network. But this is something that Tom will probably have to do since it's a DNS setup and a signup.
BattleMaster already uses Cloudflare and it's CDN. This really only helps with images, as everything else is generated on the fly by the BM server and changes dynamically.