At a guess, it was built years ago by an agency selected on the basis of anything other than technical competence. As a result it probably has thousands of hard coded HTTP links and an oddly configured out of date web server.
Given the 'encryption is only used by terrorists' climate, spending the time and money to make it work for https sounds like a hard sell.
No sources, but I have done some work in UK public sector and that kind of story would match.