What it is
HSTS is a response header telling browsers to only ever contact this domain over HTTPS, for a stated length of time. Sites that meet the requirements can also submit themselves to the preload list, which ships inside browsers so even a first-ever request is covered.
Why it matters
Without it, the first request a user makes is usually plain HTTP, and that request can be intercepted before any redirect gets a chance to run. HSTS also stops a user clicking through a certificate warning, which is the step most on-path attacks rely on.