1. Set up HTTPS on every site you run. No, really. That static 10 page info site for your church group? Yup, get it set up! The no-CSS blog from 1991 (before they were blogs)? Set it up! Even if you don't use WordPress (god, please tell me you are not running WordPress without SSL), and your site never lets anyone POST/PUT/DELETE/PATCH to it, remember that what people are reading is just as important. If I can hijack your site at the local coffee shop and serve malware, your readers will not be pleased. If I manage to do this in a widespread fashion, Google/Bing will blacklist your site and nobody will get to it.
2. Get a free cert! The dirty secret is that all certs are basically equal (EV and wildcard notwithstanding, though they are an entirely different matter). There are at least two places to get decent free certs: StartSSL and CloudFlare. If you want to protect something but your 10 page church website, get a cert from Namecheap for $8/year.
3. Use HTTPS-only. TFA is a great example: it's posted on a blog that can be accessed by both HTTP and HTTPS. If you leave this configuration, it's almost as bad as not having HTTPS at all. People don't type in "https://...". They go straight to "example.com" or they'll just Google "example" and click on the first link. Set up your server to redirect from port 80 straight to the canonical HTTPS version of your site.
If you are unfamiliar with how to set this up: practice. Get a Digital Ocean box for a few hours ($0.10/hour) and a free cert from StartSSL. Use a random domain name you own (you'll need a proper second level domain, but chances are you have one parked somewhere) and try setting up a site. It'll cost you as much as a single stick of gum and you'll know that much more about how to do it.
Edit:
4. Use a strong cipher suite such as this one: https://support.cloudflare.com/hc/en-us/articles/200933580-W...
5. Use nginx, at least for front-end proxy. Your life will be easier.
6. Check your setup against https://www.ssllabs.com/ssltest/analyze.html. Fix issues it highlights.
7. Don't lose your private key. Don't have it live only on the live server.
8. Use HSTS (http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security) but beware that once you have it set, you cannot go back to plain HTTP. For almost everyone this should not be a problem.