I agree with the need for the BBC to do this. But I disagree with the OP's suggestion that, just because it took them until now to finish doing it, that I should be "afraid of their security practices".
The "afraid of the security practices" was more of a joke than an actual serious jab. But I do still hold that site-wide TLS should be default by all major websites at this point in time.