I saw a recent announcement regarding updates to allow the site to be run using an SSL certificate. Have you considered using Lets Encrypt? It's a free, open-source implementation for acquiring and renewing SSL certificates. This allows you to minimize your operating costs while providing secure browsing to your users.
The only catch I can think of is that the certificate won't work for users on XP prior to SP3 (hopefully a vast minority of your users).
Thoughts?