A lot of this presentation is mooted by understanding PQC as an scientific question rather than an engineering one. What are the precise natures of quantum-superior attacks on cryptosystems and what are key establishments and signatures that resist those attacks? Whatever else you think of quantum cryptanalysis those are undeniably important theoretical questions.
A few more slides are mooted by the likelihood that any mainstream deployed PQC system is going to be hybridized with a classical cryptosystem.
As an articulation of a threat model for modern computing, it simultaneously makes some sense and proves too much: if you think OWASP-type vulnerabilities are where everyone's head should be at (and I sort of agree), then all of cryptography is a sideshow. I'm a connoisseur of cryptographic vulnerabilities that break real systems the way SQL injection does (a bitflipping attack on an encrypted cookie, a broken load-bearing signature scheme) but even I have to admit there's 1 of those for every 10,000 conventional non-cryptographic attack.
But of course, it also depends on who your adversary is. Ironically, if you're worried about state-level SIGINT, the barrier for OWASP-style attacks may be higher than that of large-scale codebreaking; passive interception and store-now-decrypt-later is the SIGINT love language.
My biggest thing with all of this is a core belief about organizations like NSA: that they exist primarily to secure budget for NSA. Given that, the one thing you absolutely don't want to do is have a system that is breakable only at almost-implausible cost.
(Also, his RSA-1024 analysis is off; it's missing batch attacks).